Via gncrypto.news
Bitcoin Red Team scans hundreds of projects, identifies over 1,000 critical vulnerabilities using AI
A volunteer squad of 16 auditors used open-weight AI models to tear through nearly 400 Bitcoin repositories in about 30 hours, and the results are sobering.
A group of 16 volunteers just did in 30 hours what would normally take professional audit firms months. The Bitcoin Red Team, a grassroots security initiative, scanned roughly 390 open-source Bitcoin-related projects and surfaced 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities.
The effort wasn’t academic. It was triggered by a very real, very expensive disaster.
The Coldcard exploit that started it all
The Bitcoin Red Team’s audit sprint was a direct response to a firmware vulnerability in Coldcard hardware wallets. That flaw, buried in the device’s random-number generator, led to estimated losses between $70 million and $114 million in stolen Bitcoin.
In English: the thing responsible for generating your private keys was broken, which meant attackers could predict those keys.
The scale of the losses caught the attention of Calle, a well-known Bitcoin developer, and Rob Hamilton, CEO of AnchorWatch. Together they organized the Red Team campaign in late July and early August 2026, assembling volunteers and securing funding from OpenSats, the open-source Bitcoin grant organization.
Total expenditures for the initiative came in at over $40,000.
How AI supercharged the audit
The team leaned heavily on open-weight AI models to accelerate the scanning process. The toolkit included models like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, each deployed through a custom-built security harness designed specifically for this kind of rapid vulnerability discovery. The team plans to open-source that harness.
Across the 16 volunteers working over the roughly 30-hour sprint, the team averaged approximately 2.31 high or critical findings per person-hour.
The verification problem
Only about 21.4% of the findings had been independently reproduced at the time of reporting.
The team filed their results directly with project maintainers, creating a pipeline for responsible disclosure.
What this means for investors
The Coldcard exploit that catalyzed this effort is a case study in how hardware wallet security failures can translate directly into financial losses. Somewhere between $70 million and $114 million in Bitcoin disappeared because of a single firmware bug in a device marketed as the gold standard of self-custody.
For investors, users who rely on hardware wallets should be tracking whether their device manufacturers participate in third-party security audits and bug bounty programs.