TLDR
- A volunteer security team discovered 4,962 security vulnerabilities spanning 390 Bitcoin-related projects during a roughly 30-hour investigation
- Of these discoveries, 720 were classified as critical or high severity, though just 147 have been communicated to the responsible developers
- This comprehensive security review was initiated following the Coldcard hardware wallet compromise that resulted in over $100 million in stolen Bitcoin
- Rob Hamilton, CEO of AnchorWatch, reports that OpenAI limited his platform access, compelling him to switch to Chinese open-source AI alternatives for continued research
- OpenSats introduced a Code RED grant initiative to compensate security researchers for vulnerability disclosures and AI-related expenses
A collective of volunteer cybersecurity experts has submitted close to 5,000 vulnerability reports spanning the Bitcoin infrastructure following a significant hardware wallet security incident.
The Bitcoin Red Team conducted an analysis of 391 open-source code repositories, identifying 4,962 security vulnerabilities. A single project emerged without any flagged issues.
Among the total discoveries, 720 received high or critical severity ratings, representing approximately 14.5% of all reported findings. To date, only 147 of these urgent vulnerabilities have been communicated to the developers tasked with remediation.
The Catalyst Behind the Security Review
This extensive examination began after Coinkite’s July 30 announcement revealing that seed generation processes on certain Coldcard devices had defaulted to a vulnerable software-based method. The secure element contributed merely 32 bits of randomness, enabling attackers to brute-force private keys through approximately 4.3 billion computational attempts.
According to Galaxy Research data from August 4, confirmed losses totaled 1,596 Bitcoin stolen from approximately 7,300 wallet addresses. A potential fourth attack wave could elevate total losses approaching $130 million.
The Coldcard security incident drove active Bitcoin addresses to their highest level in 20 months on the blockchain.
Distribution of Security Weaknesses
Contrary to expectations given the Coldcard incident, hardware wallets registered the second-lowest rate of severe vulnerabilities at 9.6%. Mining pools topped the list at 21.7%, with infrastructure and development tools at 21.5%, and exchange and swap platforms at 20.9%.
Cryptographic libraries generated the highest volume of individual findings, contributing 1,385 issues across 128 separate projectsārepresenting more than one-quarter of all reported vulnerabilities.
Approximately 21.4% of reported vulnerabilities included functioning proof-of-concept exploit code. Around 91% of discoveries resulted from automated security scanning tools.
A single hour within the 30-hour investigation period accounted for 4,101 findings. This concentration resulted from incorporating Rob Hamilton’s previous independent examination, during which he invested over $10,000 analyzing more than 100 cryptographic libraries.
Calle, the anonymous physicist who developed the Cashu ecash protocol, indicated that project maintainers have been rapidly addressing the most critical vulnerability reports.
Artificial Intelligence Platform Restrictions Impact Security Researchers
Hamilton disclosed that OpenAI imposed usage restrictions the day after he began incorporating its Trust and Cyber security features into his Red Team analysis. These limitations effectively halted his ongoing investigation work.
He explained that he was forced to pivot to Chinese open-source AI platforms to continue his security research, describing the situation as personally discouraging as an American citizen.
Hamilton contended that malicious actors encounter no comparable limitations, while legitimate researchers working to enhance security face bureaucratic obstacles.
In response to these challenges, OpenSats introduced a Code RED grant program that compensates researchers for validated vulnerability disclosures and covers their artificial intelligence infrastructure costs.
Bitcoin was valued at approximately $64,396 during reporting, representing a 0.5% increase over the previous 24-hour period. The comprehensive security audit has not triggered significant market movement.


