Bearish

AI-led team flags 85 critical flaws across 390 Bitcoin projects

min

A volunteer security group, Bitcoin Red Team, led by developer Calle and AnchorWatch CEO Rob Hamilton, reported 4,962 findings across 390 open-source Bitcoin repositories within 27.5 hours of launch, including 85 critical and 635 high-severity issues, according to Bitcoin Magazine on August 5, 2026. The effort was funded with over $40,000 in AI compute by OpenSats, a 501(c)(3) supporting open-source Bitcoin development.

Scope, methodology, and AI stack

The team built a 171,599-line review harness to locate load-bearing Bitcoin libraries, document and reproduce issues locally, and produce responsible disclosure reports for maintainers. As of the latest update, 21.4% of findings were reproducible. Reported pace: roughly one critical exploit per hour per person.

Models used: Kimi K3, GPT Sol, Fable, Opus, and GLM5.2. Early access limitations to OpenAI and Anthropic led to heavier use of Chinese open-source models. Subsequent updates indicated Anthropic access for Fable and OpenAI access to GPT Sol.

The harness and broader methodology are expected to be open-sourced to allow companies to test closed-source codebases. No public website or GitHub repo is available at this time.

Catalyst: Coldcard RNG exploit

The audit was launched in response to an RNG vulnerability in Coldcard hardware wallets that enabled theft from MK3+ devices. Confirmed Bitcoin losses exceed $100 million. Galaxy Research identified at least 15 distinct attackers exploiting the flaw. Coinkite released patched firmware, but users who generated seeds under vulnerable firmware remain at risk until funds are migrated.

Boltz exchange paused operations to address AI-discovered vulnerabilities linked to the post-Coldcard security environment, indicating immediate triage across services.