The Bitcoin Beacon The Bitcoin Beacon
Network & Mining · Open Source

Volunteers Scanned Bitcoin’s Code and Found 85 Critical Bugs

Days after the Coldcard theft, a volunteer red team ran AI over 390 open-source Bitcoin projects — and turned up thousands of flaws.

By The Bitcoin Beacon · August 7, 2026 · 5 min read
Inspectors with magnifying lenses examine a towering machine of gears and locks, one marking a cracked gear, linocut
Network & Mining · Auditing the machine — Illustration: The Bitcoin Beacon

The Coldcard theft that drained more than $100 million from self-custody wallets in late July did not just cost its victims. It jolted the wider ecosystem into asking an uncomfortable question: if a bug in one popular hardware wallet could do that, what else is lurking in the open-source code that bitcoin quietly runs on?

A group of developers decided to find out. In early August, a volunteer effort calling itself the Bitcoin Red Team — led by the developer known as Calle, creator of the Cashu ecash protocol, and Rob Hamilton, chief executive of the custody firm AnchorWatch — pointed automated auditing tools at the software underpinning wallets, nodes, and payment apps. According to a Bitcoin Magazine report published August 5, the team logged 4,962 findings across 390 open-source Bitcoin repositories in its first 27.5 hours.

What they found

Raw finding counts are easy to inflate; severity is what matters. Of those thousands of results, the team flagged 85 as critical and 635 as high-severity — the classes of bug that, unpatched, can leak keys, corrupt funds, or hand an attacker control. The remainder skew toward lower-risk issues, the ordinary sediment of any large codebase. But 85 critical flaws, surfaced in barely more than a day of scanning, is a sobering yield for software that collectively guards billions of dollars.

The exercise was deliberately fast and broad rather than deep. The team leaned on AI tooling to triage an enormous surface area quickly, funded by roughly $40,000 in compute donated through OpenSats, the nonprofit that channels grants to open-source bitcoin developers. The goal was not to publish a definitive verdict on any one project but to build a map of where the soft spots cluster.

Open-source software is a commons. Almost nobody is paid to guard it.

Why it took a hack to start

The uncomfortable backdrop is that most of bitcoin’s critical infrastructure is maintained by unpaid or barely-paid volunteers. A wallet used by hundreds of thousands of people may depend on libraries with a single overworked maintainer and no security budget. That is the same structural weakness that produced the Coldcard firmware bug, and the same one that, weeks earlier, let attackers hijack a widely used software package elsewhere in the industry through a compromised maintainer account.

The Red Team’s response is to treat auditing as a public good rather than a paid service. The group says it will open-source the AI security harness it built — a framework that identifies critical libraries, reproduces vulnerabilities, packages the evidence into a report, and supports responsible disclosure to the maintainers before anything is published. If it works as intended, any developer could rerun the same scan against their own project and fix what it surfaces.

The limits

AI-assisted scanning is noisy. A large share of automated findings are false positives or low-impact style issues, and a critical rating in a triage tool is a starting point for a human reviewer, not a proven exploit. Responsible disclosure also means the specific critical bugs are not public, so outsiders cannot yet judge how many are genuinely dangerous versus theoretical. The honest read is that the count is a prompt, not a verdict.

Still, the direction is the right one. Bitcoin’s security has always rested on the idea that open code invites scrutiny — but scrutiny only happens if someone actually looks. For years, the looking was ad hoc. The Coldcard loss made the cost of not looking concrete, and the answer taking shape is a repeatable, funded, automated way to keep looking, on every project, all the time.

Why it matters: bitcoin’s guarantees are only as strong as the volunteer-built software around it — and this is the first serious attempt to audit that software at scale before the next hack, not after.

Sources

  1. Coinspeaker — Bitcoin Red Team Audit: 85 Critical Flaws Exposed
  2. Bitcoin.com News — Bitcoin Red Team Finds 4,962 Flaws After Coldcard Hack
  3. KuCoin — Bitcoin Red Team Discovers 4,962 Security Issues in 27.5 Hours
  4. Open Source For You — Bitcoin Red Team To Open Source AI Security Harness After Major Audit

Editor’s note: finding counts and severity tallies are the Red Team’s own, as reported by Bitcoin Magazine and secondary outlets; specific vulnerabilities are under responsible disclosure and not public. Automated audit ratings require human confirmation. Nothing here is financial advice.

The world’s bitcoin headlines, in your inbox every morning.

Free. Five minutes. No hype.

Subscribe free