BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Bitcoin's AI red team found 85 critical bugs in about a day

Nearly 5,000 Findings in Under 28 Hours A volunteer security initiative known as the Bitcoin Red Team has completed one of the most sweeping audits the Bitcoin ecosystem has seen. Led by Anch

AnonymousCryptoCompass newsroom
August 6, 2026
2 min read
NEWS
Bitcoin's AI red team found 85 critical bugs in about a day
CryptoCompass editorial visual for bitcoin coverage.

Nearly 5,000 Findings in Under 28 Hours

A volunteer security initiative known as the Bitcoin Red Team has completed one of the most sweeping audits the Bitcoin ecosystem has seen. Led by AnchorWatch CEO Rob Hamilton (@Rob1Ham) and Bitchat developer Calle (@callebtc), the group uncovered 4,962 security issues across 390 open-source projects during a 27.5-hour sprint on August 4 and 5, 2026.Of those findings, 85 were classified as critical and 635 as high-severity, averaging 166 findings per hour.

The team has grown to 16 globally distributed researchers working around the clock. While AI tools powered much of the throughput, the researchers noted that much of the work still involves manually guiding the AI, even as their automated harnesses continue to improve.Most of the critical reports filed so far were quickly verified by project owners, confirming the team is identifying real vulnerabilities.

Sparked by the Coldcard RNG Exploit

The audit was a direct response to a serious security breach affecting Coldcard hardware wallets. A vulnerability introduced in Coldcard firmware 4.0.0 in March 2021 caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by non-secret chip data.An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.Total losses have since climbed to more than $130 million, according to blockchain-monitoring firms.

Canada-based Coinkite, whose affected Coldcard wallets were drained, warned that the vulnerability "is a warning for every company building Bitcoin hardware and software, not only us." That warning appears to have galvanized the broader developer community into action.

Funding for the Red Team effort came from OpenSats (@OpenSats), a nonprofit that supports open-source Bitcoin development, which contributed nearly $40,000 to cover AI compute costs. The team is now planning to open-source the tools it built during the sprint, enabling other Bitcoin companies to run ongoing audits of their own codebases. The goal is to let projects scan their own closed-source code before attackers do.

Bitcoin Magazine: Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos | Bleeping Computer: Coldcard Wallet RNG Flaw Likely Linked to $88 Million Bitcoin Theft | TechCrunch: Hackers Steal Over $130M by Exploiting Bug in Offline Hardware Wallets