Bitcoin Red Team Uncovers Nearly 5,000 Potential Vulnerabilities
A group of volunteer coders and AI assistants, known as the Bitcoin Red Team, conducted a sweeping security audit of hundreds of open-source Bitcoin projects. In just over 30 hours, they uncovered nearly 5,000 potential security problems, with 85 classified as critical and 635 as high-severity.
The team used automated scans to identify vulnerabilities, but human contributors were involved in the process to validate the findings. The audit targeted tools people use to hold and move bitcoin, including wallets, libraries, and applications.
Privacy-focused software returned the highest proportion of high-or-critical findings at 24%, while cryptographic libraries generated the largest raw volume of findings (1,101) but only a 10% high-severity rate. The audit's pace was impressive, with an average of roughly 1.85 serious issues per project reviewed.
Only 19 projects have had their findings reported upstream to maintainers so far, adding stress to already overworked developers. The team has signaled it plans to open-source the tools behind the sprint, which were backed by nearly $40,000 in funding from OpenSats.