A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin-related projects in roughly 27.5 hours, an average of 166 findings per hour, according to a report published August 5 by pseudonymous Cashu developer calle, who co-led the effort alongside AnchorWatch co-founder and CEO Rob Hamilton.

Of the total findings, 85 were classified as critical and 635 as high severity, together accounting for 14.5% of everything filed. The group says it reproduced roughly 21% of findings with a working proof of concept and retired only eight as false positives, a low error rate for a sprint run at that pace.

a black rectangular object with a white logo on it
Photo by Jonathan Borba on Unsplash

The audit leaned heavily on AI agents that contributors prompted independently, with 91% of findings arriving through automated scan intake rather than manual review. Calle described the process as "hand holding the AI" rather than fully autonomous scanning, noting that different prompting strategies from different contributors surfaced different classes of bugs across the same codebases.

Where the risk concentrated

Findings were not evenly distributed by category. Privacy and coinjoin tools had the highest concentration of serious issues, with 24% of their findings rated high or critical. Swap and exchange infrastructure followed at 21%, and payment or merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume of findings, 1,101, but only 10% of those were high or critical, suggesting broader but shallower issues in that category.

The average project reviewed carried 1.85 serious issues, and as of the report's publication only 19 of the 390 projects, fewer than 5%, had received formal disclosure of the findings filed against them, with the remainder still working through private notification.

A response to the Coldcard exploit

The sprint was organized as a direct response to a vulnerability disclosed in Coinkite's Coldcard hardware wallet, one of the most widely used cold-storage devices in Bitcoin's self-custody ecosystem. Ledger Chief Technology Officer Charles Guillemet pointed to the broader implications of AI-assisted review for hardware security. A related 2021 Coldcard firmware flaw involving inadequate random number generation had already cost users an estimated $130 million, a vulnerability researchers say likely would have surfaced faster under this kind of AI-assisted review.

The scale of the sprint's output is already reshaping how some projects operate. Boltz, a non-custodial swap service, temporarily halted swaps after its team found itself unable to keep pace with the volume of AI-generated attack reports surfacing in real time, according to reporting from Atlas21. OpenSats contributed close to $40,000 to fund the volunteer effort, a modest budget that organizers say was stretched considerably further by the AI tooling doing the bulk of the scanning work.

Related: LBank Adopsi Chainlink Data Streams untuk Prediksi BTC dan ETH yang Lebih Cepat

Calle said the 16-person team, a mix of human contributors and automated agents, was averaging roughly one critical-severity exploit per hour per person at the sprint's peak, with all findings reported privately to maintainers before any public disclosure.