Bitcoin Red Team identified 4,962 possible security flaws in 390 open-source projects related to the Bitcoin ecosystem. The initiative brought together 16 researchers over 27.5 hours and found 85 vulnerabilities classified as critical and another 635 of high severity.

The operation combined artificial intelligence-assisted analysis with manual code review. The group was created after a firmware flaw associated with the Coldcard hardware wallet caused estimated losses of more than US$ 116 million in bitcoin.

Some of the flaws still need to be confirmed

The numbers represent the findings recorded during the first stage of the audit, but not all of them have had their exploitation proven.

As of the time described by the group, approximately one in five problems had been independently reproduced. Validation is necessary to determine which vulnerabilities can actually be exploited.

Bitcoin Red Team was led by developer Calle and Rob Hamilton, CEO of self-custody insurance company Anchorwatch.

OpenSats, a nonprofit organization that funds open-source projects related to Bitcoin, allocated about US$ 40,000 to the initiative.

Privacy tools concentrate critical flaws

Projects related to privacy and coinjoin concentrated 24% of the vulnerabilities considered critical, despite representing a smaller share of the analyzed repositories.

Cryptographic libraries recorded the highest total number of findings, with 1,101 occurrences. About 10% of the flaws found in this category received a high-severity classification.

Most of the 390 projects presented few or no critical vulnerabilities. The most serious problems were concentrated mainly in tools responsible for private key generation, transaction signing, and privacy-focused mechanisms.

Coldcard attack motivated audit

The review began after a problem in Coldcard firmware, whose origin is reportedly related to code that has existed since March 2021.

The incident resulted in the withdrawal of more than 1,800 BTC from more than 5,200 addresses. Accumulated losses exceeded US$ 116 million, according to data presented in the base text.

Canadian users accounted for approximately a quarter of the stolen amounts.

Bitcoin Red Team considers the audit only the first phase of the work. The group intends to review the pending findings, confirm which flaws can be exploited, and coordinate responsible disclosure of the issues with the affected projects before publishing technical details.

More from Radar