News

Bitcoin Red Team Flags 4,962 Risks in Rapid AI Security Sweep

Bitcoin Red Team reviewed 390 open-source projects in about 30 hours. Volunteers reported 4,962 potential flaws. Researchers reproduced only 21.4%, leaving most reports unconfirmed while developers awaited evidence of genuine and exploitable threats.

Written By : Yusuf Islam
Reviewed By : Manisha Sharma

The Bitcoin Red Team reported 4,962 potential security findings after an AI-assisted review of 390 open-source Bitcoin projects completed in roughly 30 hours. The 16-member volunteer group identified 85 possible critical flaws and 635 high-severity findings. Researchers had reproduced only 21.4% of all reports when Calle shared the latest update.

AI Review Finds Thousands of Possible Flaws

The globally distributed team includes Bitcoin developer Calle and AnchorWatch CEO Rob Hamilton. Bitcoin-focused nonprofit OpenSats funded more than $40,000 in AI services for the campaign. Calle said the review produced 720 findings rated high or critical. That rate equaled about 2.31 serious findings per volunteer each hour during the review.

During part of the campaign, Calle also reported nearly one potential critical exploit per volunteer each hour. Still, the team treated the results as leads rather than confirmed attacks.

Human Testing Separates Signals from False Alarms

The group used AI models to scan repositories, identify suspicious code and help researchers test possible attack paths. The systems searched for weak randomness, access errors, memory faults and unsafe software interactions.

Traditional audits often require weeks or months because researchers must learn unfamiliar code and reproduce complex failures. By comparison, AI tools allowed the volunteers to inspect far more code within a short period.

Yet automated reviews can generate false positives, duplicate reports, and issues that real systems cannot exploit. How many of the remaining reports will survive full reproduction and developer review?

Also Read: Missouri Men Face Bitcoin Robbery Case as BTC Rebounds Above $64K

Coldcard Losses Raise Stakes for Bitcoin Projects

The campaign followed the discovery of a serious seed-generation flaw in several Coldcard hardware wallet firmware versions. The defect weakened the randomness used to create some recovery seeds. Attackers reportedly stole about 1,816 BTC from more than 5,200 addresses across four waves of suspicious transactions. Bitcoin carried an estimated value of $116 million at the time.

The weakness allowed skilled attackers to reconstruct private keys without possessing affected devices. CoinKite released corrected firmware, but an update cannot repair seeds created with vulnerable software.

CoinKite advised affected users to install the fixes, create new recovery seeds and move funds to new addresses. It said seeds created with 50 private dice rolls avoided this specific randomness flaw alone.

The company also urged developers to test build processes, submodules, dependencies, and compilation settings during AI reviews. Meanwhile, Bitcoin Red Team expects to release its custom security harness as open-source software.

Conclusion

Bitcoin Red Team’s AI-assisted sweep produced 4,962 potential findings across 390 projects, including 720 high or critical reports. However, researchers reproduced only 21.4%. Bitcoin teams must verify each result, test build systems and dependencies, and issue fixes wherever confirmed risks affect deployed software.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Coldcard Bitcoin Theft Splits as 64 BTC Moves Through Wasabi Mixer

Best Crypto Hardware Wallets in 2026

BlackRock’s Rare ETHA Reverse Split Makes Trading Ethereum 70x Cheaper: Here’s How

ChangeNOW Brings Martin Masser Into Its Crypto Super App

Ripple Partner SBI Seals $289M Bitbank Takeover in Landmark Crypto Deal