
A volunteer Bitcoin security initiative has identified 4,962 potential security issues across 390 Bitcoin projects during its first 30-hour sprint, with 720 classified as high or critical severity. According to reports from X/Calle, the Bitcoin Red Team launched this coordinated security review covering Bitcoin libraries, wallets, infrastructure software and other open-source projects following the recent Coldcard wallet attacks. The volunteer effort includes 16 volunteers using AI-assisted tooling alongside manual verification to identify software vulnerabilities. The sprint was funded by OpenSats, a U.S. 501(c)(3) nonprofit that covered approximately $40,000 in AI token costs for the comprehensive review.
The team reported that 21% of reported issues have already been reproduced, indicating that a portion of the initial AI-generated findings have been independently verified. As reported by X/Calle, the group is "averaging on the order of 1 critical exploit per hour per person" and had already reported critical vulnerabilities to several projects within the previous 12 hours. The campaign spans cryptographic libraries, wallet software, infrastructure components and other projects that form part of the Bitcoin ecosystem, with the work relying on multiple testing harnesses developed specifically for the effort. Most critical reports filed were quickly verified by project owners who received them, demonstrating the effectiveness of the human-assisted AI approach.
The review effort follows one of the largest known wallet security incidents affecting Bitcoin users in recent years. According to Galaxy Research, attackers stole 1,816 BTC from approximately 7,300 addresses across three confirmed attack waves, while also identifying 14 smaller incidents linked to the same Coldcard seed-generation flaw. The research firm has separately identified a suspected fourth coordinated wave that could raise total losses to about 2,055 BTC, though additional victim confirmation is still pending. The Coldcard sweeps, which began July 30 and have taken as much as $114 million from wallets whose seeds were generated by faulty firmware, stemmed from a bug that had been dormant since 2021 and required no access to the physical device once the affected key space was known.
The Coldcard vulnerability originated during a firmware change introduced in March 2021 while integrating a new cryptographic library. According to Coinkite, instead of generating wallet seeds with the intended hardware random-number generator, vulnerable firmware versions relied on a deterministic pseudo-random generator provided by MicroPython during seed creation. Coinkite estimates affected Mk2 and Mk3 devices generated roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices produced approximately 72 bits instead of the intended 128 bits. The firmware bug silently routed seed generation through a weak software PRNG instead of hardware randomness from March 2021 through 2026, leaving funds at risk for five years before anyone caught it.
The security review revealed surprising patterns across different Bitcoin project categories, with hardware wallets and firmware ranking second lowest for serious flaws at 9.6%. According to X/Calle, mining pools hit 21.7%, infrastructure and tooling 21.5%, and swaps and exchanges 20.9%. Privacy tools topped the table at 24%, though reviewers covered only three of them. Crypto libraries carried the volume, producing 1,385 findings across 128 projects, representing more than a quarter of the corpus. The team noted that only 147 of the 4,962 findings have reached maintainers who have to fix them, with 246 findings carrying no severity label at all.