After the recent Coldcard hardware wallet vulnerability that Bitcoin Magazine said was exploited for more than $100 million, a new industry-wide security review has begun to sweep through Bitcoin open-source software. The publication reported that the group informally known as the Bitcoin Red Team has audited more than 390 repositories and identified 85 critical flaws.

The report said users of Coldcard wallets who have not moved their bitcoin to new seeds generated in secure firmware remain at risk. It added that it may still be possible to act in time, pointing readers to the relevant advisory.
4,962 findings logged in 390 projects
Bitcoin Magazine said the effort is being led by software engineer Calle, described in the article as the creator of the Android version of Bitchat, and by Rob Hamilton, chief executive of Bitcoin self-custody insurance company Anchorwatch. The project has secured funding, with more than $40,000 spent in AI tokens to audit more than 390 open-source repositories across Bitcoin.
In the latest update cited by the article, Calle said: “27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour.”
The article described the initiative as an AI-driven security audit that is already having an impact across the industry. It also noted the meme-filled reaction online, where some posts jokingly cast Hamilton and Calle as the CEO and CTO of Bitcoin.
Boltz paused operations as AI-driven attack attempts escalated
Bitcoin Magazine said that, while reports of ongoing thefts from MK3+ Coldcards tied to an RNG bug were still unfolding, Boltz exchange announced it would pause operations to catch up with AI-driven hacking attempts.
The Red Team review is using Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, which the article described as some of the most expensive and advanced models available on the market.
According to the report, access to OpenAI and Anthropic models was limited at first, which pushed the effort to rely more heavily on Chinese open-source models. The article said many people in the industry viewed that as a bad sign for U.S. AI dominance. As the project gained visibility after last week’s Coldcard hack, the team established and confirmed connections with OpenAI, giving it access to GPT Sol. Hamilton’s mention of Fable in an Aug. 4 post, the article said, suggests Anthropic-related access has also been secured.
OpenSats covers costs; no public site or GitHub page yet
The report said expenses last tallied at more than $40,000 have been covered by OpenSats, a 501(c)(3) nonprofit that funds open-source Bitcoin development projects.
Bitcoin Magazine also said the Bitcoin Red Team does not currently have a website or a GitHub repository that can be linked publicly. Still, the group includes many people across the Bitcoin industry. Individuals publicly thanked for support include, but are not limited to, danielabrozzoni, lylepratt, stutxo, benthecarman, and thesimplekid.
Custom harness built for testing and reporting
Hamilton said a custom harness has been built and is evolving quickly. At one point, the system consisted of 171,599 lines of code. The article said the harness is designed to identify and test critical Bitcoin software libraries and high-load-bearing code, identify and document vulnerabilities, reproduce them, and package verified data into reports that can be delivered responsibly to engineers.
Hamilton also said the Red Team wants to open-source the harness so Bitcoin companies can run it against their own closed-source code.
The team is actively contacting relevant open-source projects where critical vulnerabilities have been found. The article said social media screenshots shared in a humorous tone show a broader sense of dread among engineers when they receive unexpected direct messages from Hamilton or Calle.
The story linked to Calle’s post here: https://x.com/callebtc/status/2085035257477190080
Hamilton says AI works best with domain expertise
Among the public takeaways shared during the review, Hamilton said engineers with specific subject-matter expertise can sometimes produce higher-value results from the harness. In his description, the system may be able to “smell out something is wrong,” while still missing niche context. The point, as framed in the article, is that AI and human expertise need to work together to surface critical vulnerabilities efficiently.
Coldcard exploit described as a “spiritual attack” on self-custody
Hamilton also shared personal reflections after several days of Red Team work tied to the Coldcard breach. He said the vulnerability in Coldcard random number generators, and the hackers’ exploitation of that bug, amounted to a “spiritual attack” on Bitcoin and on the industry’s self-custody ethos, adding, “I mean that in the literal sense of the words”.
After expressing grief for the losses suffered by many Bitcoin users during what the article called a historic hack, Hamilton ended his post on a defiant note: “While things are not easy right now. I have the highest conviction ever in my life that the idea and technology of Bitcoin is worth fighting for. To that end. There is no Bitcoin without self-custody. This is non-negotiable.”
The story was written by Juan Galt and first appeared in Bitcoin Magazine.


