Bitcoin's AI red team found 85 critical bugs in about a day
A volunteer group called the Bitcoin Red Team, led by AnchorWatch CEO Rob Hamilton and Bitchat developer Calle, used AI tools to file nearly 5,000 security findings across 390 open-source Bitcoin repositories in just 27.5 hours, uncovering 85 critical vulnerabilities in the wake of the Coldcard RNG exploit.
Nearly 5,000 Findings in Under 28 Hours
A volunteer security initiative known as the Bitcoin Red Team has completed one of the most sweeping audits the Bitcoin ecosystem has seen. Led by AnchorWatch CEO Rob Hamilton (@Rob1Ham) and Bitchat developer Calle (@callebtc), the group uncovered 4,962 security issues across 390 open-source projects during a 27.5-hour sprint on August 4 and 5, 2026. Of those findings, 85 were classified as critical and 635 as high-severity, averaging 166 findings per hour.
The team has grown to 16 globally distributed researchers working around the clock. While AI tools powered much of the throughput, the researchers noted that much of the work still involves manually guiding the AI, even as their automated harnesses continue to improve. Most of the critical reports filed so far were quickly verified by project owners, confirming the team is identifying real vulnerabilities.
Sparked by the Coldcard RNG Exploit
The audit was a direct response to a serious security breach affecting Coldcard hardware wallets. A vulnerability introduced in Coldcard firmware 4.0.0 in March 2021 caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by non-secret chip data. An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Total losses have since climbed to more than $130 million, according to blockchain-monitoring firms.
Canada-based Coinkite, whose affected Coldcard wallets were drained, warned that the vulnerability "is a warning for every company building Bitcoin hardware and software, not only us." That warning appears to have galvanized the broader developer community into action.
Funding for the Red Team effort came from OpenSats (@OpenSats), a nonprofit that supports open-source Bitcoin development, which contributed nearly $40,000 to cover AI compute costs. The team is now planning to open-source the tools it built during the sprint, enabling other Bitcoin companies to run ongoing audits of their own codebases. The goal is to let projects scan their own closed-source code before attackers do.
Bitcoin Magazine: Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos | Bleeping Computer: Coldcard Wallet RNG Flaw Likely Linked to $88 Million Bitcoin Theft | TechCrunch: Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













