Key Highlights
- Independent security analysts documented 4,962 vulnerabilities spanning 390 Bitcoin-related projects within approximately 30 hours
- Among these discoveries, 720 were classified as high-severity or critical threats, though merely 147 have been communicated to relevant development teams
- This comprehensive security assessment was initiated following the Coldcard hardware wallet compromise, resulting in over $100 million in stolen Bitcoin
- AnchorWatch’s CEO Rob Hamilton reports OpenAI blocked his account access, compelling him to utilize Chinese open-source artificial intelligence platforms for continued analysis
- OpenSats introduced a Code RED grant initiative to compensate security researchers for vulnerability disclosures and offset their AI-related expenses
A coalition of volunteer cybersecurity experts has submitted approximately 5,000 vulnerability disclosures throughout the Bitcoin infrastructure following a comprehensive security assessment sparked by a significant hardware wallet security incident.
The volunteer Bitcoin Red Team examined 391 repositories containing open-source code and identified 4,962 distinct security weaknesses. Remarkably, only a single project passed inspection without flagged concerns.
Among the total discoveries, 720 received classifications of high-severity or critical status. This represents approximately 14.5% of all documented findings. To date, only 147 of these urgent security concerns have been successfully delivered to the development teams capable of implementing fixes.
Origins of the Security Investigation
The comprehensive examination began following Coinkite’s July 30 announcement revealing that seed generation procedures on certain Coldcard devices had reverted to a vulnerable software algorithm. The secure element contributed merely 32 bits of randomness, enabling potential attackers to compromise keys through approximately 4.3 billion computational attempts.
According to Galaxy Research analysis, verified theft incidents totaled 1,596 Bitcoin distributed across roughly 7,300 wallet addresses by August 4. A suspected fourth attack campaign could elevate aggregate losses approaching $130 million.
The Coldcard security incident drove active Bitcoin wallet addresses to their highest on-chain level in 20 months.
Distribution of Security Weaknesses
Contrary to expectations given the Coldcard catalyst, hardware wallet projects registered the second-lowest concentration of severe vulnerabilities at 9.6%. Mining pool software exhibited the highest rate at 21.7%, with infrastructure and development tools following at 21.5%, and decentralized exchange protocols at 20.9%.
Cryptographic libraries generated the largest absolute number of flagged issues. These components contributed 1,385 security concerns distributed across 128 separate projects, representing more than one-quarter of aggregate findings.
Approximately 21.4% of documented vulnerabilities included functional proof-of-concept exploit demonstrations. Automated scanning methodologies identified roughly 91% of all issues.
A single hour within the 30-hour investigation period captured 4,101 findings independently. This concentration resulted from incorporating AnchorWatch CEO Rob Hamilton’s previous independent assessment, during which he invested more than $10,000 analyzing over 100 cryptographic libraries.
Calle, the anonymous physicist who developed the Cashu ecash protocol, indicated that project maintainers have been rapidly validating and addressing the most critical vulnerability reports.
Artificial Intelligence Platform Restrictions Create Obstacles
Hamilton disclosed that OpenAI imposed access limitations on his account the morning following his incorporation of the company’s Trust and Cyber security features into his Red Team methodology. The restriction effectively halted his investigation progress.
He explained that this forced transition to Chinese-developed open-source AI platforms for continuing his security research, describing the situation as personally disappointing from an American perspective.
Hamilton contended that malicious actors encounter no comparable restrictions, whereas legitimate security researchers attempting to enhance ecosystem safety face administrative barriers.
OpenSats addressed this challenge by establishing a Code RED grant program. The initiative provides financial compensation for validated security disclosures and reimburses researchers for artificial intelligence platform expenses.
Bitcoin was exchanging hands near $64,396 during publication, representing a 0.5% increase across the preceding 24-hour period. The security audit findings have not triggered observable market volatility.





