
A Bitcoin security initiative says it identified 4,962 potential issues across 390 open-source projects during a large-scale review using artificial intelligence.
Known as the Bitcoin Red Team, the campaign began after Coinkite disclosed a serious entropy-generation flaw affecting several COLDCARD hardware-wallet models.
Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7
— calle (@callebtc) August 5, 2026
We're running a large-scale ecosystem security audit across bitcoin code bases.
27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.
We're at… pic.twitter.com/iRCylprbY1
Coinkite has released corrected firmware and advised affected users to replace vulnerable seeds and migrate their funds.
The company’s advisory provides instructions for affected devices.
Organizers said the Red Team grew to 16 people working across multiple time zones.
Its situation report covered cryptographic libraries, wallets, Bitcoin infrastructure, node implementations, Lightning software, hardware-wallet firmware, exchanges and other projects.
“27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues,” organizer Calle said in a campaign update.
A finding is an issue flagged for investigation, not necessarily a confirmed or exploitable vulnerability.
The report said severity levels were assigned by reviewers, while 21.4% of findings had been dynamically reproduced with proof-of-concept evidence.
At the time of the report, 147 findings had been sent to project maintainers and 19 projects had received disclosures.
The team said several critical reports were quickly confirmed by project owners but did not publish a complete list of validated findings.
“Most of the critical results are reproduced with a proof of concept in local regtest environments before we report,” said Calle.
Cryptographic libraries generated the most findings, followed by software wallets and infrastructure tools. About 14.5% of the overall findings were classified as either high or critical.
The campaign combined automated scanning with human review. Participants used different AI models and prompting strategies, while researchers helped verify results and prepare reports for maintainers.
According to the situation report, 91% of findings entered the system through automated scanning.
Rob Hamilton stated that approximately $20,000 had been spent across AI services by an earlier stage of the campaign, when 150 repositories had been scanned.
Bitcoin Red Team Update:
— Rob Hamilton (@Rob1Ham) August 4, 2026
We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.
We have done over a dozen…
Organizers said OpenSats and other supporters were covering costs.
The volume of results has also created challenges. Campaign members said identifying the correct maintainers and delivering useful reports had become bottlenecks.
They acknowledged that project developers were receiving a large number of security alerts and said they were working to improve filtering and reduce unreliable AI output.
Hamilton added that the group plans to release its security harness as open-source software, allowing developers and companies to run similar reviews against public or internal code.
The campaign’s final impact will depend on how many findings maintainers confirm and resolve.
Its initial results nevertheless show how AI-assisted tools can increase the speed and scale of security reviews, and the amount of verification required afterward.
