A 16-person volunteer team called Bitcoin Red Team found nearly 5,000 potential vulnerabilities across the ecosystem in just 30 hours. They reviewed 390 open-source projects and flagged 4,962 issues. The speed came from AI assistance, which helped the group identify dangerous code patterns and test attack scenarios faster than traditional manual audits would allow.
Not all findings represent real exploitable holes. Only 21.4% of them had been successfully reproduced when the team reported results. Still, the sheer volume points to a gap between how much code exists and how thoroughly it gets reviewed. Developers including Bitcoin builder Calle and AnchorWatch CEO Rob Hamilton led the effort, which was funded by the nonprofit OpenSats and cost over $40,000 in AI services.
Why AI Changes the Game
Manual security audits typically consume weeks or months because researchers need to understand unfamiliar codebases and trace complex attack paths. An AI system can scan for unsafe assumptions, broken randomness, access-control gaps and memory problems across hundreds of projects simultaneously. The human specialists then validate whether findings are genuine and matter for the actual software configuration.
During the campaign, the team produced roughly 2.31 high- or critical-level findings per person per hour. At peak efficiency, individual volunteers identified approximately one potential critical exploit per hour. That rate would be almost impossible through traditional manual work.
The group built a custom security harness and plans to release it as open-source software. This could let other Bitcoin companies audit both their public repositories and proprietary code without building their own tools from scratch. Similar automation challenges have surfaced elsewhere in tech, where testing controls need careful oversight.
The effort comes after a serious vulnerability in Coldcard hardware wallet firmware exposed the ecosystem to attack. Hackers exploited a flawed seed-generation process to steal approximately 1,816 BTC worth around $116 million from over 5,200 addresses across four waves.
This report is informational only and does not constitute financial or security advice. Always conduct your own due diligence before trusting security claims or making investment decisions.



