AI-led team flags 85 critical flaws across 390 Bitcoin projects
A volunteer security group, Bitcoin Red Team, led by developer Calle and AnchorWatch CEO Rob Hamilton, reported 4,962 findings across 390 open-source Bitcoin repositories within 27.5 hours of launch, including 85 critical and 635 high-severity issues, according to Bitcoin Magazine on August 5, 2026. The effort was funded with over $40,000 in AI compute by OpenSats, a 501(c)(3) supporting open-source Bitcoin development.
Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7
We're running a large-scale ecosystem security audit across bitcoin code bases.
27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.
We're at… pic.twitter.com/iRCylprbY1
— calle (@callebtc) August 5, 2026
Scope, methodology, and AI stack
The team built a 171,599-line review harness to locate load-bearing Bitcoin libraries, document and reproduce issues locally, and produce responsible disclosure reports for maintainers. As of the latest update, 21.4% of findings were reproducible. Reported pace: roughly one critical exploit per hour per person.
Models used: Kimi K3, GPT Sol, Fable, Opus, and GLM5.2. Early access limitations to OpenAI and Anthropic led to heavier use of Chinese open-source models. Subsequent updates indicated Anthropic access for Fable and OpenAI access to GPT Sol.
The harness and broader methodology are expected to be open-sourced to allow companies to test closed-source codebases. No public website or GitHub repo is available at this time.
red teaming bitcoin:
– we’ve written multiple harnesses and we’re launching a huge wave of reviews against many core bitcoin projects: crypto libs, wallets, infra, …
– situation is extremely bad.
– we’re averaging on the order of 1 critical exploit per hour per person.
– we’ve… https://t.co/9zlaaObU03— calle (@callebtc) August 4, 2026
Catalyst: Coldcard RNG exploit
The audit was launched in response to an RNG vulnerability in Coldcard hardware wallets that enabled theft from MK3+ devices. Confirmed Bitcoin losses exceed $100 million. Galaxy Research identified at least 15 distinct attackers exploiting the flaw. Coinkite released patched firmware, but users who generated seeds under vulnerable firmware remain at risk until funds are migrated.
Boltz exchange paused operations to address AI-discovered vulnerabilities linked to the post-Coldcard security environment, indicating immediate triage across services.





