A volunteer group calling itself the Bitcoin Red Team says it has filed 4,962 security findings across 390 Bitcoin projects in about 30 hours, describing the push as a large-scale ecosystem audit with AI agents handling a substantial share of the scanning work.
![]()
The campaign’s first situation report was published Wednesday by pseudonymous developer calle, the creator of the Bitcoin ecash protocol Cashu. The report says 85 findings were classified as critical and 635 as high severity. Together, that amounted to 14.5% of the total set, with an average of 1.85 serious issues per project and a filing pace of 166 findings an hour.
calle said the team has expanded to 16 people distributed globally and working 24/7. The report itself logs 17 contributors in total: 14 human contributors and three automated ones.
In a social media update, calle wrote: “Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7. We're running a large-scale ecosystem security audit across bitcoin code bases. 27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.”
Automation is doing most of the intake, but humans are still deeply involved
Much of the process remains manual, with humans effectively hand-holding the AI, calle wrote, though automated harnesses are improving. The report says 91% of findings came in through automated scan intake.
He also said letting contributors use their own preferred review methods “has proven to be the most effective strategy,” because different people prompt their agents in different ways and surface different bugs. Around 21% of the findings have already been dynamically reproduced with proof-of-concept code.
Severity rates differ sharply across project categories
The severity mix varies widely by category. Privacy and coinjoin tools posted the highest proportion of high-or-critical findings at 24%. Swaps and exchanges followed at 21%, while payments and merchant tools came in at 17%.
Cryptographic libraries and SDKs generated the largest raw volume of findings at 1,101, but only 10% of those cleared the high-severity threshold.
Maintainers are being hit with a wave of reports
So far, only 19 projects, less than 5% of the reviewed set, have had findings disclosed upstream. calle acknowledged that the campaign is landing at a hard moment for maintainers.
“We're sincerely sorry if our reports added stress to your already stressful day,” he wrote. At the same time, he argued the findings should be sent out quickly because project owners are in the best position to validate them, validation is now nearly free with AI, and anyone running the same tools is likely to arrive at the same bugs.
Eight findings have since been retired as false positives, according to the report.
The Coldcard backdrop
The audit comes as Bitcoin security assumptions face renewed scrutiny. In March 2021, Coinkite’s Coldcard wallet was tied to about $130 million in user losses after a firmware build drew wallet seeds from a software fallback instead of the device’s hardware random number generator, leaving private keys guessable.
In a post-mortem, the firm said it was likely that “someone used AI to review previous versions of our firmware.”
Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the episode showed AI was now being used to identify vulnerabilities in crypto code “at machine speed.” He added that “open source and reviewed are not the same thing,” and said the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it.
Guillemet said defenders now need to move at the same speed as attackers, something groups such as the Bitcoin Red Team are now putting on display.

