Bitcoin Red Team Flags 85 Critical Bugs Across 390 Projects After Coldcard Attack

By Muhammad Hassan // August 6, 2026 @ 01:49 PM Make AlphaWire Logo preferred on Google News

Share

Bitcoin Red Team Flags 85 Critical Bugs Across 390 Projects After Coldcard Attack

Share

Points of Focus

  • Bitcoin Red Team filed 4,962 potential findings across 390 projects in 27.5 hours.
  • The audit classified 85 issues as critical and 635 as high severity.
  • Human verification and disclosure routing remain the main bottlenecks.

 

 

A volunteer Bitcoin security group has filed thousands of potential vulnerability reports across the ecosystem as developers intensify code reviews following the Coldcard wallet attacks

The campaign shows how quickly AI-assisted tools can expand security coverage, though each finding still requires human verification before developers can treat it as an exploitable flaw.

Bitcoin Red Team said 16 contributors filed 4,962 findings across 390 projects in 27.5 hours. The total included 85 critical and 635 high-severity classifications, a rate of 2.31 high or critical findings per person per hour. The audit covers wallets, cryptographic libraries, infrastructure software and other Bitcoin-related codebases.

 

 

Bitcoin Red Team uses AI to scan 390 projects

Calle, the pseudonymous Cashu developer coordinating the effort, said contributors use different models, prompts and testing harnesses. Much of the work still requires engineers to guide the tools, reproduce findings and prepare reports. He described the security situation as ‘extremely bad’ and said the team had reported critical vulnerabilities to several projects.

 

 

The scale of the review has made disclosure coordination the main bottleneck. AnchorWatch CEO Rob Hamilton said the group had spent about $20,000 across services after scanning 150 repositories during an earlier phase. He identified intake, report preparation and delivery to the correct maintainers as the main choke points.

 

Most Bitcoin Red Team findings await verification

The 4,962 findings represent a review queue rather than 4,962 confirmed vulnerabilities. AI security tools can produce duplicate, low-impact or invalid reports, and Calle said the group is still improving how it filters low-quality results. He added that most critical reports are reproduced through proofs of concept in local test environments before being sent to project owners.

The Coldcard incident gives the audit urgency. Block’s independent firmware analysis found that vulnerable Coldcard software bypassed the hardware random-number generator and used a deterministic fallback after a March 2021 change. Coinkite estimated that affected Mk2 and Mk3 devices produced about 40 bits of effective entropy, while Mk4, Mk5 and Q models produced about 72 bits instead of the intended 128 bits.

Verification and remediation now determine how much security value the audit delivers. The team’s 27.5-hour update listed 85 critical cases but didn’t state how many affected projects had issued fixes.

Share

Default avatar

Muhammad Hassan

Muhammad Hassan is a tech writer with over 11 years of experience in the crypto space. He specializes in crafting data-driven strategic content that helps blockchain and fintech brands grow their organic reach. He has led editorial initiatives for global crypto media outlets, where his strategies and article series have reached millions of readers worldwide.

Table of content

Ad

Related Articles