A volunteer group of Bitcoin developers has logged nearly 8,000 potential security flaws across the ecosystem’s open-source projects in the space of a single week, a rapid-fire audit set off by one of the worst wallet hacks in the network’s history. The 16-person “red team” started with close to 5,000 flagged issues and had grown that tally to 7,958 by the weekend, according to a report from Cointelegraph’s Hodler’s Digest. Of those, 168 were classified critical and 1,120 rated high severity.

Developer Calle, who is involved in the effort, said the pace of discovery has been striking. “We’re averaging on the order of 1 critical exploit per hour per person,” Calle said, describing AI-assisted code review tools as a force multiplier that let a small volunteer group cover ground that would normally take a much larger team weeks to review manually.

a laptop and a computer
Photo by Rohan on Unsplash

A Five-Year-Old Flaw

The audit was triggered by the discovery that Coinkite’s Coldcard hardware wallets had been generating seed phrases with partially predictable randomness since March 2021. A misconfiguration in the firmware’s build process caused some devices to fall back on a software pseudorandom number generator instead of the hardware RNG the product was designed around, a defect that went undetected for more than five years before it was fixed on July 30.

What people are describing as a “fallback” wasn’t an intentional design decision or a shortcut in the seed-generation logic — it was inherited behavior from the underlying platform that became active because of a link-time error.

That single line of broken configuration proved extraordinarily costly. Attackers who reconstructed the predictable seed values drained roughly 7,300 wallets, with later estimates putting the total closer to 1,596 BTC lost across a suspected fourth wave of thefts — well north of $100 million at current prices, and the third-largest crypto hack of 2026. July’s crypto theft total across the industry reached $247 million, meaning the Coldcard incident alone accounted for a substantial share of the month’s losses.

Volunteers Race to Find the Next One

The red team’s mandate isn’t limited to Coldcard’s codebase. Volunteers are combing through wallets, libraries and infrastructure tools across the broader Bitcoin ecosystem on the theory that if one widely-used hardware wallet shipped a randomness bug for half a decade undetected, similar defects are plausibly hiding elsewhere. The rapid growth in flagged issues — from under 5,000 to 7,958 in a matter of days — suggests the group expects that number to keep climbing as the review continues.

Related: Bitcoin's BIP-110 'Anti-Spam' Fork Dies After Just Two Blocks

A Tense Moment for Bitcoin’s Developer Community

The security scramble lands amid an unrelated but simultaneous flare-up over Bitcoin’s governance. A separate proposal to filter non-financial data like Ordinals inscriptions off the network drew opposition from MicroStrategy’s Michael Saylor, who warned it “threatened Bitcoin’s neutral rules,” and Blockstream chief executive Adam Back, who cautioned the change could “damage Bitcoin’s credibility.” The proposal collapsed into a minority chain that mined only two blocks before stalling out. The overlap of a contentious protocol fight with a live security crisis has left little room for the ecosystem to catch its breath this month.

For now, Coinkite has shipped a firmware fix and affected users are being urged to migrate funds to freshly generated wallets. Whether the red team’s haul of nearly 8,000 flagged issues turns up another incident on the scale of the Coldcard bug remains the open question hanging over the effort.