16 Humans, 3 Bots, 4,962 Bugs: Bitcoin Red Team Hits One Critical Find Per Hour 🐛
Back to feed

16 Humans, 3 Bots, 4,962 Bugs: Bitcoin Red Team Hits One Critical Find Per Hour 🐛

A volunteer security group called Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin-related projects in roughly 30 hours, according to a situation report published Wednesday by pseudonymous developer calle, creator of the Bitcoin ecash protocol Cashu. Of those findings, 85 are rated critical and 635 high severity, with 21.4% so far dynamically reproduced with proof-of-concept code. "We're averaging on the order of 1 critical exploit per hour per person," calle wrote in a post on X.

The campaign runs with 16 people working around the clock, supplemented by three automated agents, and currently files findings at a pace of about 166 per hour. Calle said the group is largely "hand holding the AI," though 91% of submissions arrived through automated scan intake, and that allowing each contributor to use their own preferred review method "has proven to be the most effective strategy," because different prompts surface different bugs. The effort includes Bitcoin developer Calle and Rob Hamilton, CEO of custody firm AnchorWatch.

Severity distribution varies sharply by category. Privacy and coinjoin tools posted the highest share of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, of which about 10% met the high threshold. Eight findings have been retired as false positives, and only 19 projects, under 5% of those reviewed, have had issues disclosed upstream. "We're sincerely sorry if our reports added stress to your already stressful day," calle wrote, while arguing findings should be released quickly because project owners are best placed to validate them and similar automated tools will reach the same results.

The campaign comes days after a disclosed compromise of Coinkite's Coldcard hardware wallet tied to a March 2021 firmware build that drew wallet seeds from a software fallback rather than the device's hardware random number generator, an incident in which attackers stole more than $100 million worth of $BTC, with Galaxy putting losses at roughly $130 million. Hardware wallet maker Ledger said the Coldcard exploit should serve as a warning for the cryptocurrency industry, with Ledger CTO Charles Guillemet pointing to weaknesses in how some devices generate and store secrets. The Red Team's report lands Bitcoin's open-source maintainers into that same scrutiny window while the audit continues to run.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.