The Bitcoin Red Team identified 85 critical and 635 high-severity flaws in 390 open-source Bitcoin repositories following the Coldcard exploit that cost users over $100 million.
Led by software engineer Calle and Anchorwatch CEO Rob Hamilton, this 16-person team leveraged advanced AI models to conduct an extensive security audit in under 30 hours.
Prompted by Coldcard’s $100 Million Breach
The findings, reported on August 5, 2026, underscore a proactive community effort to bolster the Bitcoin ecosystem’s cybersecurity. Their work highlights the increasing reliance on artificial intelligence in uncovering vulnerabilities that could otherwise lead to significant financial losses for users.
The urgent audit was triggered by a catastrophic vulnerability in Coldcard hardware wallets, specifically an RNG (Random Number Generator) bug affecting MK3+ models. This flaw allowed hackers to exploit seeds generated before a fixed firmware release, leading to more than $100 million in lost bitcoin, with some reports citing over $88 million.
The breach sent ripples through the industry. Boltz exchange, for instance, announced a temporary pause in operations to address its own systems against what it described as AI-driven hacking attempts. This vulnerability served as a stark reminder of the sophisticated threats facing self-custody solutions, prompting the community to act decisively.
AI-Driven Audit Unearths Widespread Vulnerabilities
The Bitcoin Red Team’s rapid success stems from its innovative methodology, combining AI-assisted code scanning with critical human verification. This approach allowed them to process a vast amount of code quickly, scanning 390 open-source projects, ranging from core Bitcoin components to various wallets and libraries.
During the intense audit, which spanned just 29.8 hours, the team filed a total of 4,962 findings. Calle noted the remarkable efficiency, stating, “27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour.”
He added that they were “averaging on the order of 1 critical exploit per hour per person.”
The team deployed cutting-edge AI models, including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2. Initially, limitations on accessing proprietary models from OpenAI and Anthropic led to an increased reliance on Chinese open-source models. However, as the project gained traction following the Coldcard incident, connections were established, granting the team access to powerful tools like GPT Sol and Fable.
Harnessing AI and Human Expertise
A custom-built “harness,” reportedly comprising 171,599 lines of code, was central to the Red Team’s operation. This sophisticated tool is designed to identify and rigorously test critical Bitcoin software libraries, pinpointing vulnerabilities, reproducing them, and packaging the data into actionable reports for engineers.
Rob Hamilton emphasized the symbiotic relationship between AI and human intelligence in this process. He explained that while the AI harness could often detect potential issues, engineers with specific subject matter expertise were crucial for high-value results.
They could provide the “niche context” needed to fully understand and address a flaw that AI might only “smell out.” The team plans to open-source this harness, allowing other Bitcoin companies to run it against their closed-source codebases, fostering broader security improvements.
Funding, Community Support, and Future Outlook
The significant expenses for this ambitious project, tallying over $40,000 for AI tokens alone, were covered by OpenSats. This 501(c)(3) non-profit organization is dedicated to funding free and open-source Bitcoin development projects, demonstrating the community’s collective commitment to enhancing security.
Beyond the technical findings, Hamilton reflected on the Coldcard vulnerability as a “spiritual attack” on Bitcoin and its core ethos of self-custody. Despite the losses and the ongoing challenges, his resolve, and that of the Bitcoin Red Team, remains firm. “There is no Bitcoin without self-custody. This is non-negotiable,” he asserted, highlighting the fundamental principle driving these security efforts.
This concentrated audit serves as a bellwether for the future of cybersecurity in open-source software, particularly within the crypto space. Researchers anticipate that Bitcoin will be among the first industries to face a continuous wave of AI-assisted vulnerability discovery.
The Red Team’s initiative, and its intention to open-source its security tools, could set a new standard for proactive defense against increasingly sophisticated threats across the entire digital landscape.
