Technology

Bitcoin Red Team's AI Audit Flags 85 Critical Flaws Across 390 Repos

A volunteer Bitcoin security team scanned 390 open-source repositories in 27.5 hours using AI, surfacing 85 critical and 635 high-severity findings across wallets, crypto libraries, and infrastructure, with the harness set to go public.

4 min read
A security researcher's hands hover over a mechanical keyboard in a dim server room, the blue glow of multiple terminal screens reflecting off rows of humming black rack-mounted servers
Share

A volunteer team funded by OpenSats proved $40,000 in AI compute and 16 motivated people can do what professional audit firms would charge millions and months to accomplish.

Key takeaways

  • AnchorWatch Co-Founder and CEO Rob Hamilton and developer Calle led a 27.5-hour coordinated sprint across 390 Bitcoin repositories, filing 4,962 total findings including 85 critical and 635 high-severity issues, with all critical disclosures privately reported to maintainers before any public release.
  • The team's custom AI security harness is being open-sourced, giving any Bitcoin project a no-vendor-lock-in pipeline for continuous automated security review.
  • Only 21.4% of findings have been independently reproduced so far; the real test is whether maintainers patch confirmed criticals and whether the harness becomes a durable fixture rather than a one-cycle response to the Coldcard Mk3 exploit.

The Bitcoin Red Team, a volunteer security initiative funded by OpenSats, completed a 27.5-hour coordinated audit sprint scanning 390 open-source Bitcoin repositories and filing 4,962 findings, including 85 critical and 635 high-severity vulnerabilities, per updates from team leaders Rob Hamilton and Calle on X. The effort was triggered by the Coldcard Mk3 RNG firmware vulnerability, exploited in late July 2026, which swept funds from hundreds of wallets. Loss estimates across sources range from roughly 594 BTC ($38M) in the initial wave to over 1,800 BTC ($116M) in total across all waves, depending on scope and confirmation method.

The sprint involved 16 globally distributed volunteers working around the clock, spending over $40,000 in AI compute costs funded entirely by OpenSats, the 501(c)(3) nonprofit supporting open-source Bitcoin development. The effort had no corporate sponsor and no VC funding, and it moved fast.

From 150 Repos to 390: How the Sprint Escalated

Hamilton's August 4 update reported the team had already scanned approximately 150 repositories and filed more than a dozen private vulnerability disclosures at a cost of roughly $20,000 in AI compute. That was the midpoint.

By the sprint's end, Calle posted the full accounting on X:

"27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We're at 2.31 h+c findings per person per hour."

The team's AI security harness was built on open-weight models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, run through a custom security pipeline. The team leaned on Chinese open-weight models early in the sprint before OpenAI access was connected. Hamilton's earlier post described the inflection point, noting the arrival of Kimi K3 in open weights and the team's intent to accelerate.

The harness is being open-sourced so any Bitcoin company can run similar audits against its own codebase, including closed-source software.

What This Actually Changes

The Coldcard bug had been present in public firmware since approximately 2021. Five years. The code was auditable by anyone. Nobody audited it systematically.

That gap has a name: "open source" has never meant "audited." It has meant auditable, which is a different thing entirely. The Red Team just demonstrated that $40,000 in AI compute and 16 volunteers can scan 390 repositories in 27.5 hours. Professional security firms charge millions and take months for comparable scope. That cost asymmetry is now public knowledge, and the tooling to replicate it is being handed to the ecosystem for free.

Hamilton framed the stakes plainly: "There is no Bitcoin without self custody. This is non negotiable." Every critical finding quietly patched by this team is a Coldcard-class disaster that doesn't happen. The value lies in the structured reports now sitting in maintainers' inboxes, not in the finding count.

The open-source AI angle matters too. The team's early reliance on Kimi K3 and GLM5.2 (Chinese open-weight models) before OpenAI access was connected signals something the community should be watching: the most capable freely deployable AI tools for adversarial security work are predominantly non-American, which is a data point on access constraints worth taking seriously.

There is a risk embedded in the output. The reproduction rate stands at 21.4%, meaning roughly four in five flagged findings haven't been independently confirmed. If the harness ships with high false-positive rates and small open-source maintainers spend their limited bandwidth chasing noise rather than real bugs, the tool could generate audit fatigue across the exact projects that need the most help. That's the failure mode to watch, not the finding count.

What to Watch

The thesis here is straightforward: this is a repeatable security pipeline, not a one-time panic response. The trigger that disproves it is clear. If the open-source harness never ships, or if fewer than a meaningful fraction of the 85 confirmed critical findings get patched and publicly disclosed within 90 days, or if a subsequent exploit hits a repo that was scanned and cleared, the one-time-panic interpretation wins.

The full sprint details are documented in TFTC's prior coverage. Maintainers who believe their project was among those scanned can reach Hamilton directly at @Rob1Ham on X.

Sources

Frequently Asked Questions

The Red Team's audit targeted the surrounding ecosystem: wallets, cryptographic libraries, and infrastructure software. Bitcoin Core and the base-layer protocol were not in scope.

OpenSats is a 501(c)(3) nonprofit that funds open-source Bitcoin and freedom-technology development. The Red Team's entire compute budget, over $40,000, came from OpenSats with no corporate sponsor or venture capital attached.

The team has not publicly named all repositories reviewed. If you run or contribute to an open-source Bitcoin project, Rob Hamilton (@Rob1Ham) has publicly invited maintainers to reach out directly on X.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.