Bitcoin Red Team Uncovers Over 7,900 Code Flaws in Ecosystem-Wide Audit
Bitcoin's Red Team launched its largest offensive security campaign to audit the Bitcoin open-source ecosystem. The team, led by developer Calle, aimed to strengthen Bitcoin's defenses against AI cyber threats.
The campaign followed a $100 million hardware wallet hack, which exposed a flaw in Coldcard devices that generated private keys with weak software random number generators instead of secure hardware ones. This reduced security entropy down to 40 bits on Mk3 models and 72 bits on newer models.
The team evaluated 501 active open-source projects across the Bitcoin ecosystem, discovering 7,958 total code flaws in the process. The results showed that 16.2% represented high vulnerabilities, including 168 critical bugs and 1,120 issues that could threaten user security.
To find these flaws, the team combined manual code reviews with AI tools, spending over $58,000 on AI processing and running 75% of tasks through the Kimi K3 model. The researchers will update severity scores using feedback from software maintainers.