BackRob Hamilton

Rob Hamilton

Bitcoin Red T
2026-08-06 01:17:52

Bitcoin Red Team Flags Nearly 5,000 Issues in AI-Assisted Review of 390 Projects

Bitcoin Red Team, a volunteer security group of 16 members, found 4,962 potential issues across 390 Bitcoin ecosystem projects within 29.8 hours using AI-assisted review. Among them, 720 were rated high or critical severity, with 21.4% reproducible. The review followed the Coldcard hardware wallet incident, which saw over $100 million in Bitcoin stolen.

580
Bitcoin Red Team Flags Nearly 5,000 Issues in AI-Assisted Review of 390 Projects
Bitcoin
2026-08-05 20:33:06

Bitcoin Red Team says it found 85 critical flaws across 390 open-source repos after the Coldcard breach

A Bitcoin industry security push has accelerated after the recent Coldcard hardware wallet vulnerability, which Bitcoin Magazine said was exploited for more than $100 million. According to the report, a group referred to as the Bitcoin Red Team, led by software engineer Calle and Anchorwatch CEO Rob Hamilton, has spent more than $40,000 in AI tokens to audit more than 390 Bitcoin-related open-source repositories. In an update cited by the publication, Calle said the effort had logged 4,962 findings across 390 projects after 27.5 hours of work, including 85 critical issues and 635 high-severity problems. The team is using models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2. Bitcoin Magazine said access to OpenAI and Anthropic-related tooling improved as the initiative gained traction following last week’s Coldcard incident. The report also said OpenSats, a 501(c)(3) nonprofit focused on Bitcoin open-source development, has covered the project’s expenses. Hamilton said the team built a custom harness, at one point made up of 171,599 lines of code, to identify, test, reproduce, and document vulnerabilities in critical Bitcoin software libraries and high-load-bearing code. He added that the Red Team plans to open-source the harness so Bitcoin companies can test their own closed-source code.

660
Bitcoin Red Team says it found 85 critical flaws across 390 open-source repos after the Coldcard breach
Coldcard
2026-07-31 07:43:46

Coldcard seed-generation flaw linked to 594 BTC drained in 25 minutes

Coinkite has confirmed a seed-generation flaw affecting parts of the Coldcard hardware-wallet line, after on-chain analysts tracked the theft of 594.48 BTC in a burst of transactions completed within roughly 25 minutes. The incident involved 1,324 UTXOs swept through 500 transactions across a three-block window, with the funds taken from about 500 single-signature addresses. Security researchers said the issue traces back to firmware changes introduced in March 2021 that accidentally disabled the secure chip’s hardware random-number generator, leaving key generation to rely on predictable inputs such as a chip serial number and clock registers. Coinkite first focused its warning on the Mk3, then later expanded the affected scope to include older firmware on the Mk4, Mk5 and Q. The company said users should not wait for a firmware update and should move funds by creating a new seed on an unaffected device, verifying backups, testing with a small transaction and then transferring the full balance. Devices including TAPSIGNER, OPENDIME and SATSCARD were said to be outside the affected codebase.

610
Coldcard seed-generation flaw linked to 594 BTC drained in 25 minutes
Coinkite
2026-07-31 02:46:06

Coinkite warns of potential seed risk in Coldcard Mk3 as $38.3 million BTC transfer comes under review

Coinkite, the Canadian hardware wallet maker behind Coldcard, issued a security warning on July 31 urging users of the Coldcard Mk3 to move funds if their seed phrases were generated on firmware versions 4.0.1 through 5.0.3. The company said its preliminary analysis suggests wallets protected with a BIP-39 passphrase face lower risk, while Mk4, Q and Mk5 devices are not affected. At the same time, security researchers are examining an unusual transfer involving 594.48 BTC, worth about $38.3 million. AnchorWatch CEO Rob Hamilton said the attacker moved 1,324 UTXOs through 500 transactions within three blocks and suggested the issue may stem from insufficient randomness during wallet generation. Wizardsardine CEO Kevin Loaec said the flaw could be tied to a software library, a secure chip, or a low-entropy random number generator linked to a specific device batch or firmware version. He also said AI-generated scripts may have been used to brute-force affected wallets. No conclusive evidence has yet linked the transfer directly to a Coldcard Mk3 flaw.

700
Coinkite warns of potential seed risk in Coldcard Mk3 as $38.3 million BTC transfer comes under review