The volunteer-led Bitcoin Red Team identified 4,962 potential vulnerabilities across 390 Bitcoin-related repositories in under 30 hours of AI-assisted code review, the group disclosed on Tuesday, following the Coldcard wallet firmware exploit.
The initiative, launched in the wake of the high-profile Coldcard wallet exploit, has already classified 720 findings as high or critical severity, while more than one-fifth of reported issues have been independently reproduced.
The coordinated effort aims to strengthen Bitcoin’s software stack before additional vulnerabilities can be exploited, reflecting growing urgency among developers and security researchers.
Coldcard exploit triggers industry-wide security review
The Bitcoin Red Team was formed just days after attackers exploited a firmware vulnerability in Coldcard hardware wallets, one of the industry’s most widely used self-custody solutions.
According to Bitcoin developer Calle, the initiative is reviewing Bitcoin wallets, cryptographic libraries, infrastructure software, and other open-source repositories using a combination of artificial intelligence and manual verification.
“We’re averaging on the order of one critical exploit per hour per person.” — Calle, Bitcoin developer, via X.
Calle also described the current security landscape as “extremely bad,” adding that several critical vulnerabilities had already been privately disclosed to affected maintainers rather than released publicly to avoid exposing users before patches become available.
The team said approximately 21.4% of its reported findings have already been successfully reproduced through human verification.
According to Calle, OpenSats is funding roughly $10,000 per day in computing costs, while AI company Moonshot has provided access to its Kimi K3 model to support large-scale code analysis.
The project is also seeking additional community support to sustain ongoing reviews.
Nearly 5,000 findings expose broader ecosystem risks
Rather than focusing exclusively on wallet software, Bitcoin Red Team expanded its review across hundreds of repositories that collectively support Bitcoin’s infrastructure.
The initiative reported: 390 repositories reviewed, 4,962 potential vulnerabilities identified, 720 high or critical severity findings, and 21.4% of findings independently reproduced.
Although many of the reported issues are still undergoing validation, the scale of the findings illustrates the growing complexity of securing Bitcoin’s expanding software ecosystem.
Security researchers emphasized that AI is being used to accelerate code discovery, while every significant finding undergoes manual review before responsible disclosure to developers.
Coldcard vulnerability remains at the center of concern
The security campaign follows one of Bitcoin’s most significant wallet incidents in recent years.
Galaxy Research previously confirmed that attackers exploited a weakness in Coldcard’s firmware that reduced the randomness used during wallet seed generation, allowing attackers to derive private keys under certain conditions.
Researchers linked multiple coordinated attack waves to the flaw, with estimated losses approaching $89 million worth of Bitcoin across more than 1,000 wallets.
Coinkite later acknowledged that the vulnerability originated from a firmware update introduced in March 2021, when the software mistakenly relied on a deterministic pseudo-random generator instead of the intended hardware random-number generator.
The company released emergency firmware updates and warned users that simply installing updated firmware is not sufficient for wallets created with vulnerable versions.
“Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet.” — Coinkite Security Advisory.
Block’s Bitcoin Engineering and Security team independently reached similar conclusions, stating that affected firmware generated significantly weaker entropy than originally intended.
Investors urged to prioritize operational security
While Bitcoin itself has not been compromised, the latest developments reinforce an important distinction for investors: protocol security and software security are not the same.
The Bitcoin Red Team’s findings suggest that vulnerabilities can emerge throughout the broader ecosystem, including wallet firmware, cryptographic libraries and infrastructure software that millions of users depend on.
The initiative continues to report newly discovered vulnerabilities privately to project maintainers as reviews expand across additional repositories.
For investors, the campaign serves as a reminder that secure self-custody extends beyond owning a hardware wallet.
Keeping firmware updated, generating new recovery seeds when recommended, verifying software sources and monitoring official security advisories remain essential practices for protecting digital assets.
As security researchers continue auditing Bitcoin’s open-source infrastructure, the industry is likely to see increased collaboration between developers, AI-assisted security initiatives and independent auditors to reduce systemic risks before they can be exploited.