Bitcoin Red Team Discovered 4,962 Potential Vulnerabilities in 390 Bitcoin Projects

8/6/2026, 10:36 AMЕвгения Слив

The Bitcoin Red Team volunteer group has published a large-scale report on the state of security in the ecosystem of the first cryptocurrency. The researchers identified 4,962 potential vulnerabilities in 390 different projects covering wallets, cryptographic libraries, and infrastructure software. Of the total number of findings, 85 were classified as critical, and another 635 were classified as high-risk. The campaign was initiated after high-profile attacks on Coldcard hardware wallets, the total damage from which, according to Galaxy Research estimates, could reach $ 130 million. In the first 30 hours of work, the team managed to reproduce more than twenty percent of the detected problems. Sixteen specialists are participating in the initiative, including the developer of the Cashu protocol under the pseudonym Calle and Rob Hamilton, CEO of AnchorWatch, who use the "red team" method to simulate the actions of hackers.

To find errors, experts combine manual code verification with the capabilities of modern AI models and their own tools for local attack testing. The reason for the audit was a critical error in Coldcard devices that occurred due to changes in the 2021 firmware. It turned out that the devices sometimes used a predictable MicroPython software random number generator instead of a hardware one. This led to a catastrophic decrease in the entropy of the LEDs from 128 bits to 40 bits for the Mk2 and Mk3 models, and up to 72 bits for newer versions. Coinkite has already released fixes, but users are strongly advised to create new wallets and transfer funds, as the old keys are actually compromised. The developer of Calle noted that the ecosystem is currently in chaos, and researchers are finding an average of one critical exploit per hour.

The organizers called the main difficulty of the campaign not the search for vulnerabilities itself, but the coordination of the process of their responsible disclosure. Rob Hamilton emphasized that transmitting information to the right developers takes significantly longer than scanning repositories. The use of artificial intelligence significantly speeds up error detection, which is confirmed by the recent example of the Anthropic team, which found 22 vulnerabilities in the Firefox browser. However, the exponential growth in the number of reports creates an additional burden on developers, who do not always have time to implement fixes promptly. The Bitcoin community continues to discuss the need to implement stricter security and auditing standards for open source projects that manage user funds.

Popular news