Bitcoin's Red Team Hit the Outreach Wall
Bitcoin's Red Team logged 1,029 high-or-critical findings across 425 projects in 55 hours. Now comes the hard part: reproducing the bugs and reaching the maintainers.

TFTC - Truth for the Commoner Bitcoin Brief | |||||||||||||||||
Sup, freaks. URGENT BTCPAY SERVER WARNING: BTCPay Server says a critical vulnerability is being actively exploited and can result in the loss of funds. If you run BTCPay Server, update to version 2.4.2 immediately. If you cannot update right away, turn the server off until you can. There is a more thorough description in the first Signal below. Before we get into today's Brief, I want to reiterate something. I am absolutely gutted by what unfolded with COLDCARD. Matt and I recommended COLDCARD to freaks for years. People trusted that recommendation, and some of them lost bitcoin. I am deeply sorry. Matt and I spent Monday's Rabbit Hole Recap #421 working through what happened, what we got wrong, and how we are thinking about accountability from here. Nothing I write below erases the damage. The response from the Bitcoin Red Team gives me hope, but it does not absolve me of the responsibility that comes with the recommendation we made. Let's get into it. | |||||||||||||||||
LEAD STORY | |||||||||||||||||
Bitcoin's Red Team Hit the Outreach WallThe Bitcoin Red Team started as an emergency response to the COLDCARD disaster. Less than three days later, it had expanded into a coordinated security review covering hundreds of projects. Calle's 55-hour situation report put the effort at roughly 24 people, 425 projects scanned, about 6,700 findings, and 1,029 findings classified as high or critical. The team was moving through around 7.7 projects per hour. It is an insane pace. We need to be honest about what those numbers mean. They come from the campaign dashboard. They are not an audited list of CVEs, and 1,029 high-or-critical classifications does not mean 1,029 confirmed exploits. Rob Hamilton has been very clear that model output includes slop, overstatement, and flat-out wrong calls. A human still has to reproduce the bug, understand the context, determine the severity, and work with the maintainer on a fix. The human layer is where the Red Team hit the wall. Calle reported that only about 19.5% of the scanned projects had a The scanners are moving at machine speed. Responsible disclosure is still hunting around for an email address. Rob's August 5 operations note explained why the people doing the triage matter so much. At that point the campaign had reviewed more than 300 repositories and spent roughly $40,000. Rob said developer feedback and repeated human direction improved the harness output almost immediately. The models can cover a ridiculous amount of ground. The people closest to the code still know where to point them and which findings actually matter. OpenSats stepped up on Thursday and gave this effort a home. Code RED will prioritize support for people red-teaming critical Bitcoin software and reimburse past LLM token costs. The dedicated Red Team Fund is live. The application also draws the right lines. Do not paste vulnerability details into the form. A grant is not permission to attack somebody else's system. Find the bug, reproduce it, disclose it privately, and help get it fixed. The service disruptions around the ecosystem need to be treated separately. ZEUS said its incident was limited to ZEUS infrastructure, customer funds were not at risk, and Pay Lightning Addresses were back online while node and LSP services remained days away. Boltz still had not published a clean resumption notice after pausing swaps on August 3. BULL was directing users to SideSwap as a temporary L-BTC to BTC route on August 6. There is no public evidence tying either disruption to the Red Team. This week exposed how cheap vulnerability discovery has become and how unprepared many open-source projects are to receive the results. If your code touches bitcoin, publish a security contact. If you have the skills to reproduce and triage these findings, the Red Team needs you. The attackers are not going to wait for the responsible disclosure process to catch up. | |||||||||||||||||
SIGNAL | |||||||||||||||||
CRITICAL SECURITY ALERT BTCPay Server Is Under Active Exploitation. Update Now.BTCPay Server issued an emergency warning this morning that a critical vulnerability is being actively exploited and can result in the loss of funds. The project says the vulnerability affects all BTCPay Server instances. If you run one, update immediately to version 2.4.2 through Admin Dashboard > Server > Maintenance > Update, then verify that 2.4.2 appears in the footer. If you cannot update right away, turn the server off until you can. Integrators should also update NBXplorer to 2.6.10. The release includes a fix for a TOTP two-factor-authentication bypass through Greenfield Basic authentication, but the team has not yet publicly tied the active exploit to one specific code path. A full postmortem is coming. Bruno Garcia and Ben Carman reported the issues through the Bitcoin Red Team effort. Alert anyone you know who runs BTCPay Server. | |||||||||||||||||
ON-CHAIN The Network Migrated 100x What Attackers StoleJames Check's August 7 note shows just how many freaks moved their coins after the COLDCARD failure became public. Using Galaxy's roughly 2.1k BTC stolen estimate as the benchmark, Check found that about 233k BTC held by long-term holders moved, roughly 100 times the known theft total. Funded addresses fell about 0.8%, UTXO count fell about 0.4%, and the long-term-holder supply declined 1.38% from its recent high near 16.88 million BTC. Yet exchange deposits cited in the piece totaled only about 22k BTC, or roughly 10% of the long-term-holder decline. Most of this looks like a security migration, not a rush for the exits. Fees barely moved. Realised price was essentially flat. Short-term-holder cost basis slipped from about $67,900 to $67,400. The theft was catastrophic. The network absorbed a migration two orders of magnitude larger without breaking a sweat. | |||||||||||||||||
BITCOIN CULTURE PubKey's Analysis of What Unfolded This WeekPubKey convened an emergency Coin Based panel Thursday night to analyze what unfolded this week and where the ecosystem goes from here. The conversation brought together Matt Corallo, Antoine Poinsot, Alex Thorn, and Rob Hamilton, with additional guests calling in. They worked through the technical failure, the on-chain investigation, the limits of the current disclosure process, and what bitcoin projects need to change as AI makes vulnerability discovery radically cheaper. PubKey streamed the discussion on X and posted the full recording on YouTube. I highly recommend watching the whole thing. It is one of the clearest attempts I have seen this week to separate what we know, what we still do not know, and what needs to happen next. | |||||||||||||||||
AI INFRASTRUCTURE Gas Turbines Are Booking the AI Power StorySiemens Energy's third-quarter results give us a view of the physical infrastructure being pulled into the AI buildout. The company booked €17.9 billion of orders and ended the quarter with a €162 billion backlog. Gas Services accounted for roughly €73 billion of that backlog. Grid Technologies accounted for another €51 billion. Gas Services alone booked around €10 billion of new orders during the quarter. Management commentary and bank research put total gas-turbine commitments near 95 GW, with a path toward 100 GW by year-end. The global market could reach 110 to 120 GW per year through FY2030, with datacenters potentially adding another 20 GW of demand. These commitments are not operating megawatts, but they are real orders for real turbines. The AI power scramble is no longer confined to capex slides. | |||||||||||||||||
TREASURY Treasury Still Needs $739 Billion This QuarterThe federal government still has an enormous amount of paper to sell. Treasury's August 3 borrowing estimate calls for $739 billion of privately held net marketable borrowing between July and September, $68 billion more than Treasury estimated in May. The department expects to end September with a $950 billion cash balance. None of this guarantees a particular move in bitcoin, stocks, yields, or the dollar. It simply describes the supply the market has to absorb while the government continues running massive deficits. Bank desks can debate the quarter-to-quarter timing and the mix between bills and coupons. The larger point is hard to miss. The Treasury plans to borrow nearly three-quarters of a trillion dollars in three months, and the fiscal machine has no intention of slowing down. | |||||||||||||||||
| |||||||||||||||||
| |||||||||||||||||
⚡ FREEDOM TECH CORNER | |||||||||||||||||
Ship a SECURITY.md or the Scanners Cannot Reach YouThe Bitcoin Red Team is finding bugs faster than it can find the people responsible for fixing them. The situation is ridiculous and completely avoidable. If your project ships code that touches bitcoin, publish a | |||||||||||||||||
DATA SNAPSHOT | |||||||||||||||||
As of August 7, 2026, 10:31 a.m. ET | |||||||||||||||||
| |||||||||||||||||
Sources: mempool.space; TFTC Bitcoin ETF Flows. | |||||||||||||||||
| |||||||||||||||||
| |||||||||||||||||
See you tomorrow. This is not investment advice. Do your own research. | |||||||||||||||||
YouTube: https://www.youtube.com/@TFTC podcast: https://www.tftc.io/tag/podcasts/ |


