The campaign was a direct response to the July 2026 Coldcard hardware wallet exploit . Here is what happened with that hack:
In response, the Bitcoin Red Team launched its audit to find similar random-number-generator bugs, weak cryptographic practices, and other systemic flaws before attackers could exploit them .
| Metric | Number |
|---|---|
| Total findings filed | 4,962 |
| Critical-severity issues | 85 |
| High-severity issues | 635 |
| High- or critical-level combined | 720 |
| Findings reproducible on review | 21.4% |
| Repositories audited | 390 |
| Team size | 16 researchers |
The sheer volume — nearly 5,000 reports in a day — created a major triage problem for downstream maintainers . Only about one in five findings was confirmed reproducible, but the group argued that flagging borderline issues was justified given the severity of the Coldcard attack .
Rob Hamilton (AnchorWatch CEO and campaign co-lead) had enrolled in OpenAI's "Trust Cyber" program, which grants approved security researchers subsidized API access for vulnerability research . On August 8/9, 2026, after he had already integrated the program into his workflow and filed valid disclosures, OpenAI revoked his access without explanation .