Red Team Audit Finds Over 1,000 Critical Vulnerabilities in Bitcoin Projects
A team of volunteer developers, part of the Bitcoin Red Team initiative, conducted an audit sprint in late July and early August 2026. The goal was to identify security vulnerabilities in open-source Bitcoin-related projects, using AI-powered tools.
The effort was triggered by a significant loss due to a firmware vulnerability in Coldcard hardware wallets, which led to estimated losses between $70 million and $114 million in stolen Bitcoin.
The Red Team campaign scanned approximately 390 projects over 30 hours, discovering 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities. The team used open-weight AI models like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2 through a custom-built security harness.
The results showed that only about 21.4% of the findings had been independently reproduced at the time of reporting. The team filed their results directly with project maintainers for responsible disclosure.