
Bitcoin Audit Finds 85 Critical Flaws
A volunteer group calling itself the Bitcoin Red Team — 16 researchers co-led by developer Calle and AnchorWatch's Rob Hamilton — filed 4,962 security findings across 390 open-source Bitcoin projects in 27.5 hours on August 4–5, including 85 critical and 635 high-severity, per its own updates. Funded by roughly $40,000 from nonprofit OpenSats, the AI-assisted sprint was a direct response to the Coldcard exploit; the team disclosed issues privately before publication and plans to open-source its tooling.
Bitcoin Red Team: the defenders got the same superpower
Two days ago I argued the Coldcard theft showed AI cutting the attacker's costs — the same code-reading tool in both hands, and this time only the thief profited. Here's the other half of that story, and it arrived within the week. Sixteen volunteers using about $40,000 of AI compute produced nearly 5,000 security findings across 390 Bitcoin projects in twenty-seven hours — 85 of them rated critical. The 'defenders' picked up the identical superpower and pointed it the other way.
"Critical" here is the team's own pre-fix label, not 85 proven heists. Also the AI isn't working alone — the researchers describe most of the effort as still largely manual, hand-holding the models toward real bugs. However flaws that would have sat undiscovered for years, the way Coldcard's did for five, are being surfaced in hours, disclosed privately to maintainers before any attacker reads about them.
This reframes the "audits expire" problem I keep returning to. If a single audit is just a snapshot that ages the moment it's taken, the answer was never a better snapshot — it's never stopping. The most important thing this group said isn't the finding count. It's that they plan to open-source their tooling so anyone can run these scans continuously. Not audit-and-certify, but audit-and-keep-auditing, at machine speed, forever.
One Bitcoin service, Boltz, halted swaps this week because AI-driven attacks were outpacing its team — the attacker side is already here, not coming. Both sides now scan at the same speed for the same price, and neither gets to stop. That's the new equilibrium: security stops being a certificate you earn and becomes a race you run continuously, or lose. The good news from this week is that some defenders showed up to run it.
2 sources
- COINTELEGRAPH: Bitcoin Red Team reports 5K findings in sweeping security audit · cointelegraph.com · T2
- Bitcoin Red Team Finds 85 Critical Vulnerabilities in 390 Open-Source Repositories · panewslab.com · T2