A volunteer effort called the Bitcoin Red Team filed 4,962 findings across 390 open-source Bitcoin repositories in 27.5 hours, identifying 85 critical and 635 high-severity security issues using AI-driven scanning tools.

The audit was led by AnchorWatch CEO Rob Hamilton and Bitchat developer Calle. OpenSats, the Bitcoin development funder, is covering frontier model costs of $40,000 and above. The team plans to open-source its tooling so Bitcoin companies can scan their own code before potential attackers exploit flaws.

Across total value locked, last 90 days
Across total value locked, last 90 days · MSB Intel data desk

The effort was triggered by the Coldcard hardware wallet RNG exploit, which drained over $100 million from users' devices. That breach exposed how undetected vulnerabilities in widely-used code can cause large-scale financial loss. The Red Team's scope, 390 repositories in a single day, represents a compressed security audit that would typically require weeks of manual review.

MSB Intel

The 85 critical findings are the highest-severity tier in standard vulnerability classifications, meaning they can lead to immediate system compromise or data loss if exploited. The 635 high-severity issues rank just below critical and often require urgent patching. Together, these 720 issues across the top two severity tiers account for roughly 14.5 percent of the total 4,962 findings.

Bitcoin's open-source infrastructure is maintained by thousands of developers across decentralized projects. No single entity controls the codebase, which means security responsibility is distributed. Publishing tooling publicly allows any Bitcoin company, exchange, wallet provider, or node operator, to run the same AI scanning locally on proprietary code without exposing it to external auditors.

OpenSats is covering frontier model costs of $40,000 and above. The group has previously funded protocol research and developer salaries. The open-source tooling plan means future scans will not depend on continued funding from OpenSats.

The team must release the tooling and publish methodology details on a timeline to validate whether the scanning approach can be replicated across other blockchain projects and whether the 85 critical findings can be independently confirmed.