Bitcoin Red Team files 4,962 findings in 27.5 hours during massive open-source audit

7 hours ago 1



Sixteen security researchers walked into 390 open-source Bitcoin codebases and, in slightly more than a day, found nearly 5,000 things wrong. The result of an audit sprint by the Bitcoin Red Team, a volunteer group that delivered one of the most thorough security sweeps the Bitcoin ecosystem has ever seen. The numbers are bracing: 4,962 total security findings across 390 projects, logged in a 27.5-hour window spanning August 4 to 5, 2026. Of those, 85 were classified as critical and 635 as high-severity. That works out to roughly 2.31 findings per researcher per hour. What triggered the audit The sprint was a direct response to vulnerabilities recently discovered in the COLDCARD hardware wallet, one of the most widely trusted cold storage devices in Bitcoin’s self-custody culture. Funding came from OpenSats, a nonprofit that supports open-source Bitcoin development, which contributed nearly $40,000 to support the effort. The volunteer model and AI-powered tooling stretched every dollar considerably further. How AI changed the math The Bitcoin Red Team leaned heavily on AI-driven analysis tools to scan codebases at a speed no manual review could match. The team averaged 180 findings...

Read Entire Article