Bitcoin Red Team logs 4,962 security findings across 390 Bitcoin projects in AI-assisted audit

Bitcoin Red Team logs 4,962 security findings across 390 Bitcoin projects in AI-assisted audit

N
News Editor
2026-08-06 09:43:34
A volunteer group calling itself the Bitcoin Red Team says it has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, describing the effort as a large-scale ecosystem audit powered in significant part by AI agents. The first situation report, published Wednesday by pseudonymous developer calle, says 85 findings were rated critical and 635 high severity, or 14.5% of the total corpus, with an average of 1.85 serious issues per project and a filing pace of 166 findings an hour. The team said it has grown to 16 people working around the clock, while the report itself lists 17 contributors, including 14 humans and three automated systems. According to calle, 91% of findings came through automated scan intake, though much of the process still involves humans closely guiding the tools. The report also breaks down severity by category, with privacy and coinjoin tools posting the highest share of high-or-critical issues. The campaign arrives as Bitcoin wallet security is under renewed scrutiny following the Coldcard incident, which Ledger CTO Charles Guillemet said showed how AI can now identify crypto code flaws at machine speed.

A volunteer group calling itself the Bitcoin Red Team says it has filed 4,962 security findings across 390 Bitcoin projects in about 30 hours, describing the push as a large-scale ecosystem audit with AI agents handling a substantial share of the scanning work.

Bitcoin Red Team logs 4,962 security findings across 390 Bitcoin projects in AI-assisted audit 2

The campaign’s first situation report was published Wednesday by pseudonymous developer calle, the creator of the Bitcoin ecash protocol Cashu. The report says 85 findings were classified as critical and 635 as high severity. Together, that amounted to 14.5% of the total set, with an average of 1.85 serious issues per project and a filing pace of 166 findings an hour.

calle said the team has expanded to 16 people distributed globally and working 24/7. The report itself logs 17 contributors in total: 14 human contributors and three automated ones.

In a social media update, calle wrote: “Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7. We're running a large-scale ecosystem security audit across bitcoin code bases. 27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.”

Automation is doing most of the intake, but humans are still deeply involved

Much of the process remains manual, with humans effectively hand-holding the AI, calle wrote, though automated harnesses are improving. The report says 91% of findings came in through automated scan intake.

He also said letting contributors use their own preferred review methods “has proven to be the most effective strategy,” because different people prompt their agents in different ways and surface different bugs. Around 21% of the findings have already been dynamically reproduced with proof-of-concept code.

Severity rates differ sharply across project categories

The severity mix varies widely by category. Privacy and coinjoin tools posted the highest proportion of high-or-critical findings at 24%. Swaps and exchanges followed at 21%, while payments and merchant tools came in at 17%.

Cryptographic libraries and SDKs generated the largest raw volume of findings at 1,101, but only 10% of those cleared the high-severity threshold.

Maintainers are being hit with a wave of reports

So far, only 19 projects, less than 5% of the reviewed set, have had findings disclosed upstream. calle acknowledged that the campaign is landing at a hard moment for maintainers.

“We're sincerely sorry if our reports added stress to your already stressful day,” he wrote. At the same time, he argued the findings should be sent out quickly because project owners are in the best position to validate them, validation is now nearly free with AI, and anyone running the same tools is likely to arrive at the same bugs.

Eight findings have since been retired as false positives, according to the report.

The Coldcard backdrop

The audit comes as Bitcoin security assumptions face renewed scrutiny. In March 2021, Coinkite’s Coldcard wallet was tied to about $130 million in user losses after a firmware build drew wallet seeds from a software fallback instead of the device’s hardware random number generator, leaving private keys guessable.

In a post-mortem, the firm said it was likely that “someone used AI to review previous versions of our firmware.”

Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the episode showed AI was now being used to identify vulnerabilities in crypto code “at machine speed.” He added that “open source and reviewed are not the same thing,” and said the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it.

Guillemet said defenders now need to move at the same speed as attackers, something groups such as the Bitcoin Red Team are now putting on display.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
570

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.