A volunteer security group called the Bitcoin Red Team uncovered 4,962 vulnerabilities, 85 of them critical, across 390 open-source Bitcoin projects over a 27-hour stretch after the Coldcard hack.
Key Takeaways
- The Bitcoin Red Team filed 4,962 findings across 390 repositories in 27.5 hours.
- Opensats funded the audit with nearly $40,000 as 16 researchers combined AI tools with manual review.
- Privacy and coinjoin tools carried the highest share of serious flaws, at 24% of critical findings.
A Response to the Coldcard Exploit
The Coldcard hardware wallet exploit drained bitcoin (BTC) from long-term holders after a firmware bug dating to March 2021. Losses have climbed past $116 million across more than 1,800 BTC pulled from over 5,200 addresses.
That episode prompted a volunteer effort called the Bitcoin Red Team, led by BTC dev Calle alongside Rob Hamilton, CEO of self-custody insurer Anchorwatch. They launched an emergency audit of the broader bitcoin open-source ecosystem to test whether other widely used wallets and code libraries share similar weaknesses to the one that sank Coldcard users.
Image source: XSixteen security researchers spent 27.5 hours combing through 390 open-source bitcoin repositories, combining artificial intelligence (AI)-assisted analysis with manual review. The team filed 4,962 total security findings, including 85 classified as critical and 635 rated high-severity (a pace averaging 2.31 high- or critical-severity findings per researcher, per hour).
Funding for the sprint came from Opensats, a nonprofit that backs open-source bitcoin development, which contributed close to $40,000 to support the researchers’ work. Calle described the state of ecosystem security as “extremely bad.”
Analysts who tracked the audit in real time noted that only about one in five findings had been independently reproduced so far, showing that many of the flagged issues still need confirmation before developers could be certain of their real-world severity.
Where the Flaws Are Concentrated
Privacy and coinjoin tools (software designed to obscure the trail of bitcoin transactions onchain) accounted for the highest concentration of serious issues, representing 24% of critical findings despite making up a smaller share of the total projects reviewed. Cryptographic libraries, by contrast, generated the largest raw number of findings at 1,101, but a comparatively low 10% of those were rated high-severity, suggesting that code is generally more mature even though it draws the most scrutiny from researchers.
Most of the 390 projects reviewed had few or no critical issues; the real danger seemed to be concentrated in a smaller set of tools handling private key generation, signing, and privacy-preserving transactions, the same category of software at the root of the original Coldcard failure that started this whole effort.
The timing of the unearthing matters, given bitcoin’s self-custody culture has spent the past two weeks absorbing the scale of the Coldcard losses, with Canadian users alone accounting for roughly a quarter of the funds stolen.
The Future Needs Assessing
The Bitcoin Red Team has noted that the audit is the first phase of an ongoing effort rather than a one-time event, with plans to work through the backlog of findings, confirm which vulnerabilities are genuinely exploitable, and coordinate responsible disclosure with the affected projects before any details are made public.
For a self-custody culture still absorbing the size of the Coldcard losses, the audit doubles as evidence that white-hat researchers are now moving at a pace closer to that of attackers.

By Bitcoin News | Created at 2026-08-07 13:41:09 | Updated at 2026-08-07 15:29:19
4 hours ago








