Bitcoin Red Team's AI-powered code review found 4,962 potential security issues across 390 projects in just under 30 hours. That's roughly one critical vulnerability per hour per reviewer. The volunteer group classified 720 findings as high or critical severity, with over one-fifth already independently verified.

The security blitz kicked off days after attackers exploited a firmware flaw in Coldcard hardware wallets, forcing developers to take a hard look at what else might be broken. According to Bitcoin developer Calle, the group is targeting crypto libraries, wallets, infrastructure software, and open-source projects across the ecosystem. His assessment was blunt: the security situation is "extremely bad."

Speed and scale of the review

What made this possible was combining AI-assisted tooling with manual verification. AnchorWatch CEO Rob Hamilton joined other Bitcoin contributors to systematize the hunt. Calle reported that critical vulnerabilities were already being reported to affected projects within the first 12 hours. The team has expanded the scope significantly, pulling in 390 repositories and spinning up multiple test harnesses to catch different classes of bugs.

The fact that 21.4% of initial findings have been independently reproduced matters. It means the AI wasn't just throwing false positives at developers. These are real issues that need patching. The Coldcard incident served as a catalyst, pushing the community to stop waiting for zero-days to surface on their own and instead hunt for them systematically.

This article is informational. It does not constitute financial or investment advice.