The Bitcoin Red Team, a 16 person volunteer group, filed 4,962 security findings across 390 open source Bitcoin projects in 27.5 hours, including 85 critical and 635 high severity vulnerabilities — 14.5% of all findin... Only 21.4% of findings had been independently reproduced at the 29.8 hour mark, and fewer than 5...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did the Bitcoin Red Team discover in its AI-assisted audit of open-source Bitcoin projects, what was the scale and severity of the find. Article summary: ## Bitcoin Red Team AI-Assisted Audit. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
In early August 2026, a volunteer group of 16 security researchers — calling themselves the Bitcoin Red Team — accomplished what no single company or development team could: they combed through 390 open-source Bitcoin repositories in 27.5 hours and flagged nearly 5,000 potential security issues. Their AI-assisted audit found 85 critical and 635 high-severity vulnerabilities, sparking urgent conversations about the role of artificial intelligence in open-source security and a coordinated industry push for defender access to frontier AI models .
Over the course of a 27.5-hour sprint spanning August 4–5, 2026, the Bitcoin Red Team filed 4,962 total security findings across 390 open-source Bitcoin projects . Of those, 85 were classified as Critical severity and 635 as High severity — meaning 720 findings (14.5% of the total) were rated high or critical
. That works out to an average of 1.85 serious issues per project and a filing rate of 166 findings per hour
. The team's lead, developer Calle, reported an average of 2.31 high-or-critical findings per person per hour
.
The effort cost over $40,000 in AI compute tokens, funded by OpenSats (a 501(c)(3) nonprofit), OpenCode, and AnchorWatch . The team used a custom security harness that at one point contained 171,599 lines of code, integrating frontier AI models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2 to perform automated static analysis
.
By August 14, 2026 — after 108 hours of work — the team had expanded the review to 501 projects and logged 7,958 total findings, with 1,280 classified as high or critical .
The Bitcoin Red Team operated as a globally distributed squad working around the clock across time zones . The process combined AI-driven code scanning with human oversight, but the volume of results created a significant verification bottleneck.
Reproduction rate. In the first 29.8 hours, only 21.4% of findings had been successfully reproduced by human reviewers — meaning the vast majority remained unverified potential issues . At the 108-hour mark, reproduction had risen to 24.7%
. The team emphasized that these initial severity ratings represented preliminary assessments, not confirmed vulnerabilities
.
Upstream reporting. Fewer than 5% of the 390 reviewed projects had received upstream disclosure of their findings at the time of initial reporting, indicating a substantial backlog in responsible disclosure . The team followed a strict disclosure process: critical findings were privately reported to maintainers before any public release, and the team built working proof-of-concept exploits to confirm vulnerabilities before disclosure
.
Project categories most affected. Privacy and coinjoin tools carried the highest proportion of high- or critical-rated findings at 24% . Cryptographic libraries and SDKs produced the largest raw volume, at 1,101 total findings
.
The Bitcoin Red Team's audit was a direct response to the Coldcard hardware wallet RNG (random number generator) vulnerability — a critical firmware flaw in Coinkite's Coldcard that had silently routed seed generation through a weak software PRNG instead of hardware randomness from March 2021 through 2026 . The exploit enabled the theft of approximately 1,816 BTC (over $100 million) from long-term holders
.
While the Coldcard bug itself was discovered prior to the Red Team's formation, the incident demonstrated how devastating a single unpatched vulnerability in a widely trusted cold-storage device could be. Coinkite released a fixed firmware after the vulnerability was disclosed .
The Red Team's audit was the ecosystem's response: multiple findings from the AI-assisted scan — including critical issues in privacy tools and coinjoin software — were subsequently patched by maintainers after responsible disclosure .
The scale and severity of the Bitcoin Red Team's findings prompted a coordinated industry response. On August 10, 2026, the Bitcoin Policy Institute (BPI) published an open letter signed by more than 70 organizations across the digital-asset ecosystem, calling on frontier AI labs to take specific actions .
Signatories included major custodians, exchanges, mining firms, and open-source development groups: Coinbase, Strategy (formerly MicroStrategy), Block, MARA, Galaxy, BitGo, Brink, OpenSats, Trezor, Kraken, Ledger, Anchorage Digital, and Chaincode Labs among others .
The letter's core argument was that "open-source defenders today occupy the least privileged position in the AI security landscape" . The key demands were:
The coalition warned that without this access, critical financial infrastructure built on open-source Bitcoin software faces an escalating asymmetric threat where attackers operate with superior AI tools while defenders are locked out .
The Bitcoin Red Team's audit demonstrated both the power and the limitations of AI-assisted security scanning. The ability to flag nearly 5,000 potential issues in 390 projects in just over a day is unprecedented — but the low reproduction and disclosure rates revealed that human verification and responsible disclosure remain the critical bottlenecks .
The team has stated plans to open-source its AI security harness to strengthen ecosystem-wide defense . This would allow the broader Bitcoin developer community to run similar scans independently, potentially turning a one-time sprint into a durable security practice.
The fundamental question left unanswered: whether the defenders will get the AI tools they need before the attackers do.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The Bitcoin Red Team, a 16 person volunteer group, filed 4,962 security findings across 390 open source Bitcoin projects in 27.5 hours, including 85 critical and 635 high severity vulnerabilities — 14.5% of all findin...
The Bitcoin Red Team, a 16 person volunteer group, filed 4,962 security findings across 390 open source Bitcoin projects in 27.5 hours, including 85 critical and 635 high severity vulnerabilities — 14.5% of all findin... Only 21.4% of findings had been independently reproduced at the 29.8 hour mark, and fewer than 5% of projects had received upstream disclosure, highlighting a massive verification and reporting backlog.
The audit was triggered by the Coldcard hardware wallet RNG flaw that enabled theft of 1,816 BTC (over $100 million).