In its first 27.5 hours of operation, the team filed 4,962 total security findings across 390 projects . Of those, 85 were classified as critical severity and 635 as high severity, together making up 14.5% of all findings — an average of 1.85 serious issues per project at a rate of 166 findings per hour
.
However, these raw numbers come with an important caveat. As of early reports, only 21.4% of findings had been successfully reproduced by human reviewers, meaning the confirmed exploitable number is significantly lower than the raw find count . The team stressed that AI-generated reports still require human verification to determine real-world exploitability.
By August 14, 2026, the team had expanded its scan to 501 projects over 108 hours, logging 7,958 findings with 1,280 classified as high or critical . At that point, 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream to project maintainers
. Privacy and coinjoin tools had the highest proportion of high-or-critical findings at 24%
.
The most significant real-world consequence of the audit was the discovery of a critical vulnerability in BTCPay Server, an open-source Bitcoin payment processor used by merchants worldwide. On August 7-8, 2026, attackers actively exploited a flaw that allowed them to extract LND (Lightning Network Daemon) admin macaroon credentials from BTCPay Server instances — essentially the authentication keys that control Lightning nodes .
With those credentials, attackers could connect remotely to victims' LND nodes and drain funds from Lightning channels without any authentication . Affected entities included the BTCPay Server Foundation itself and Citadel21, a Bitcoin-focused community center
.
The vulnerability was responsibly disclosed by Sparrow Wallet developer Craig Raw and the Bitcoin Red Team . BTCPay Server released an emergency fix in version 2.4.2 and urged all users to upgrade immediately or temporarily shut down their servers
.
In response, the BTCPay Server Foundation offered a recovery bounty of up to 3 BTC (roughly $190,000 at the time), representing 10% of any funds recovered . The foundation also donated 0.21 BTC each to Craig Raw and the Bitcoin Red Team for their responsible disclosure
.
A major policy flashpoint emerged immediately after the audit. On August 9, 2026, OpenAI blocked Rob Hamilton from using its 'Trusted Access for Cyber' program — despite him having completed verification and onboarding — preventing further Bitcoin vulnerability research on OpenAI's models .
Hamilton reported that he began integrating OpenAI's capabilities on Saturday only to find his access restricted the following morning . 'It absolutely guts me as a patriotic American to have to do this,' he wrote on X, announcing he would return to using Chinese open-source models to continue protecting Bitcoin infrastructure
.
The Bitcoin Red Team migrated its research to Moonshot AI's open-weight Kimi K3 model, a Chinese open-source LLM . Hamilton publicly stated that adversarial hackers already have unrestricted access to frontier AI tools while defenders are locked out
.
On August 13-14, 2026, the Bitcoin Policy Institute (BPI) coordinated an open letter signed by over 40 crypto firms — including Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, and Exodus — demanding that leading AI labs (OpenAI, Anthropic, and others) provide vetted open-source security researchers with controlled early access to frontier AI models .
The signatories argued that attackers already have access to cutting-edge AI, creating an asymmetric security gap where white-hat defenders are denied the same tools needed to find and fix vulnerabilities before they are exploited . The letter did not call for AI labs to remove safety measures entirely, but instead proposed structured trusted-access programs with vetting frameworks, private code review spaces, and communication channels with lab safety teams
.