Bitcoin Red Team files 4,962 findings in 27.5 hours during massive open-source audit
A volunteer squad of 16 security researchers, armed with AI tools and nearly $40K in funding, uncovered 85 critical vulnerabilities across 390 Bitcoin projects in just over a day
Sixteen security researchers walked into 390 open-source Bitcoin codebases and, in slightly more than a day, found nearly 5,000 things wrong. The result of an audit sprint by the Bitcoin Red Team, a volunteer group that delivered one of the most thorough security sweeps the Bitcoin ecosystem has ever seen.
The numbers are bracing: 4,962 total security findings across 390 projects, logged in a 27.5-hour window spanning August 4 to 5, 2026. Of those, 85 were classified as critical and 635 as high-severity. That works out to roughly 2.31 findings per researcher per hour.
What triggered the audit
The sprint was a direct response to vulnerabilities recently discovered in the COLDCARD hardware wallet, one of the most widely trusted cold storage devices in Bitcoin’s self-custody culture.
Funding came from OpenSats, a nonprofit that supports open-source Bitcoin development, which contributed nearly $40,000 to support the effort. The volunteer model and AI-powered tooling stretched every dollar considerably further.
How AI changed the math
The Bitcoin Red Team leaned heavily on AI-driven analysis tools to scan codebases at a speed no manual review could match. The team averaged 180 findings per hour collectively.
The Red Team is reportedly planning to open-source the tools they used, which could set a new baseline for how the broader crypto community approaches security auditing.
Responsible disclosure, not reckless exposure
The Bitcoin Red Team followed a strict responsible disclosure process, reproducing critical issues locally before informing project maintainers privately.
Prior to this sprint, the group had already conducted scans of roughly 150 repositories that resulted in over a dozen private disclosures. The August audit was a dramatic escalation in both scope and urgency, driven by the COLDCARD fallout.
What this means for investors and the broader ecosystem
The Bitcoin ecosystem has long prided itself on its open-source ethos. In practice, most projects don’t receive meaningful security review unless they’re high-profile enough to attract attention or well-funded enough to pay for it.
The existence of vulnerabilities doesn’t mean funds were stolen or that Bitcoin itself is compromised. Bitcoin’s core protocol wasn’t the target here. The projects audited were the surrounding ecosystem of tools and applications that people use to interact with Bitcoin.
The costs of remediation will fall on individual project maintainers, many of whom are themselves volunteers or small teams.