Bitcoin Red Team Finds 85 Critical Flaws Across 390 Repos in 27 Hours
Triggered by the Coldcard RNG exploit, a 16-person volunteer team funded by OpenSats filed 4,962 security findings across 390 Bitcoin open-source repositories in 27.5 hours, including 85 critical and 635 high-severity flaws, all responsibly disclosed to project owners.

Triggered by the Coldcard RNG disaster, a volunteer team burned $40,000 in AI tokens to expose how thin Bitcoin's open-source security layer really is.
Key takeaways
- In 27.5 hours across August 4-5, a 16-person volunteer Bitcoin Red Team filed 4,962 security findings across 390 open-source repositories, including 85 critical and 635 high-severity flaws, all responsibly disclosed to project owners before any public announcement.
- The sprint, funded by OpenSats and co-led by developer Calle and AnchorWatch Co-Founder and CEO Rob Hamilton, was triggered by the Coldcard RNG exploit, which has drained over $88 million in bitcoin across at least 15 separate attacker groups.
- The Coldcard firmware bug silently routed seed generation through a weak software PRNG instead of hardware randomness from March 2021 through 2026, sitting undetected for five years in public code.
A 16-person volunteer security team filed 4,962 findings across 390 Bitcoin open-source repositories in 27.5 hours on August 4-5, including 85 critical and 635 high-severity vulnerabilities, per developer Calle's own update on X. Every critical report was privately disclosed to the affected project owners before any public disclosure, and most were quickly verified by the engineers who received them.
The sprint was funded by OpenSats, the U.S. 501(c)(3) nonprofit backing open-source Bitcoin development, which covered roughly $40,000 in AI model token costs. The trigger was the Coldcard RNG failure: a firmware bug introduced in version 4.0.1 (March 2021) that silently substituted a software pseudo-random number generator for the device's hardware RNG during seed generation, leaving funds at risk for five years before anyone caught it.
"27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We're at 2.31 h+c findings per person per hour," Calle posted on X.
What the Coldcard Exploit Actually Exposed
The Coldcard loss figures tell part of the story. Galaxy Research estimated over $88.6 million drained across 4,585 addresses as of early August, with subsequent estimates from multiple outlets ranging higher as at least 15 attacker groups continue to drain funds. Coinkite has patched every affected device line. Approximately 90% of stolen coins remain unmoved on-chain as of August 5, per on-chain forensics.
The deeper problem is what the bug's five-year lifespan reveals. The Coldcard firmware flaw sat in public code from 2021 through 2026, auditable by anyone, examined by almost no one systematically. "Open source" means auditable. It has never meant audited. The Coldcard disaster is what happens when those two things get conflated long enough.
The Red Team is a direct response to that gap. Co-led by Calle (@callebtc), the maintainer of Bitchat Android, and Rob Hamilton (@Rob1Ham on X), Co-Founder and CEO of AnchorWatch, the team grew to 16 globally distributed researchers working around the clock. They used a custom harness to identify high-load-bearing Bitcoin code, document vulnerabilities, reproduce them, and package findings into structured reports for the relevant engineers. The models involved included Kimi K3 and GLM5.2; OpenAI access was subsequently confirmed, with @Rob1Ham on X referencing additional model access in his August 4 posts. Early reliance on Chinese open-source models was a product of rate-limited access to U.S. frontier models, a concrete example of the AI access gap producing real security consequences for Bitcoin infrastructure.
Per Bitcoin Magazine's reporting on the sprint, Hamilton noted the team plans to open-source the harness so Bitcoin companies can run it against their own closed-source codebases.
The Math the Dollar Figures Make Plain
$40,000 in AI token spend. 85 critical findings. Over $88 million in losses from one undetected bug.
That ratio is the argument. A single critical flaw reaching production in a widely-used Bitcoin library could produce losses that dwarf the entire cost of running this kind of adversarial review. The Red Team did in one weekend what years of ad-hoc community auditing missed across 390 repositories. Hamilton's framing, per Bitcoin Magazine's reporting on his posts, was that the Coldcard exploit represented a "spiritual attack" on the self-custody ethos, and that the response is hardened resolve rather than retreat from self-custody.
The human-plus-AI structure matters here. Calle noted that engineers with specific subject-matter expertise could surface high-value findings that the AI alone might flag as suspicious but misidentify, because niche context the model lacks is exactly what a domain expert supplies. The throughput is AI-scale. The signal quality is human-calibrated.
The thesis this sprint either proves or breaks: AI-accelerated red-teaming is the fastest credible path to closing Bitcoin's open-source security gap before a worse failure arrives. The trigger that disproves it is straightforward: if a meaningful share of those 85 "critical" findings are revealed on engineer review to be false positives or theoretical non-exploitables, the approach needs significant refinement. Alternatively, if a second major exploit hits a repository the team already cleared, the method is insufficient, not just imperfect.
What to Watch
The Red Team has no public website or GitHub repository as of August 5. The harness open-sourcing, the full tally of verified critical findings, and whether OpenSats or similar structures fund a permanent version of this effort rather than a one-time crisis response are the three developments worth tracking. Any Coldcard user whose seed was generated under firmware 4.0.1 through 5.0.3 should treat existing funds as at risk and migrate now, regardless of whether the device firmware has since been patched.
Sources
Frequently Asked Questions
Any Coldcard MK3+ device whose seed was generated using firmware 4.0.1 through 5.0.3 (from March 2021 onward) is potentially compromised. Coinkite has patched affected device lines, but patching firmware does not fix seeds already generated under the flawed version. If you have not migrated to a new seed on secure firmware, treat existing funds as at risk and act immediately.
OpenSats is a U.S. 501(c)(3) nonprofit that funds open-source Bitcoin and freedom-tech development. It covered the Red Team's roughly $40,000 in AI token costs for this sprint, operating similarly to how it funds core protocol contributors.
Per Calle's update, most critical reports filed were quickly verified by the project owners who received them. The process is human-assisted: engineers with subject-matter expertise guide the AI through high-load-bearing code, catching what automated scanning would misread. The hit rate on confirmed findings suggests the approach is producing real results, not just noise.


