Bitcoin Red Team Files 4,962 Security Findings Across 390 Projects
Key Points
- Bitcoin Red Team filed 4,962 security findings across 390 projects in roughly 30 hours on August 6, 2026, with 85 critical and 635 high-severity issues identified.
- Privacy and coinjoin tools had the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21%.
- Developer calle said the team grew to 16 people working 24/7, with 91% of findings arriving through automated scan intake.
Vulnerability Pattern Reveals Cryptocurrency Security Gap
The audit findings arrive amid heightened scrutiny of Bitcoin security assumptions. Coinkite's Coldcard wallet incident in March 2021 resulted in $130 million in user losses after a firmware build drew wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable. Critically, the flaw remained in public code for more than five years before an adversary reportedly used AI to identify it. Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the incident demonstrated AI was now being used to identify vulnerabilities in crypto code "at machine speed."
Read Next

Ukraine Strikes Slavneft-Yanos Refinery, Russia's Biggest Oil Facility
2 hours ago

Fed Chair Communication Strategy Raises Transparency Questions
11 days ago
Guillemet argued that the pace of defense must now match the pace of attack, noting that "open source and reviewed are not the same thing." The Bitcoin Red Team's methodology—allowing contributors to prompt their own AI agents rather than using a single scanning method—proved effective precisely because different prompting strategies identified different bugs. Contributors working globally across 27.5 hours filed findings at an average rate of 166 per hour, with the report logging 17 total contributors: 14 human and 3 automated.
Calle acknowledged the campaign adds to an already difficult moment for project maintainers but argued rapid disclosure is appropriate because anyone running the same tools will reach the same findings. The audit represents one of the first large-scale demonstrations of AI-assisted security scanning applied to an entire software ecosystem, with implications for how open-source projects will need to validate and manage vulnerability reports at the scale AI can now generate them.
Related coverage: Ukraine Strikes Slavneft-Yanos Refinery, Russia's Biggest Oil Facility
Related Guide: Read our complete guide →
Market Outlook
The Bitcoin Red Team's audit may establish a new baseline for cryptocurrency security expectations, requiring projects to respond to AI-generated vulnerability reports at scale. If the 166-per-hour filing rate continues across broader codebases, maintainers could face thousands of reports annually, forcing adoption of automated triage and validation systems or risk security degradation through report overload.
Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.
Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.
NewsOracle Editorial
The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.
Latest coverage: Bitcoin


