Summary

  • The audit campaign, initiated by Cashu creator calle, identified 85 critical and 635 high-severity issues within its first 30 hours.
  • By allowing contributors to use their own agents, the team claims to achieve a broader range of vulnerabilities compared to a singular approach.
  • Projects related to privacy and coinjoin exhibited the highest incidence of serious issues, accounting for 24% of the total findings.

A volunteer collective known as the Bitcoin Red Team has reported a staggering 4,962 security vulnerabilities across 390 Bitcoin projects in approximately 30 hours, utilizing AI agents for extensive scanning in what they refer to as a "large-scale ecosystem audit."

The campaign's lead, pseudonymous developer calle, who developed the Cashu protocol for Bitcoin ecash, shared the initial findings in a report published on Wednesday. The audit uncovered 85 critical and 635 high-severity issues, which represent 14.5% of the total findings, averaging 1.85 serious issues per project, with a filing rate of 166 findings per hour. The team has expanded to 16 members working continuously, comprising 17 contributors, 14 of whom are human and three automated systems.

Bitcoin Red Team update: our team has grown to 16 individuals working around the clock.

We are conducting a comprehensive security audit across Bitcoin's code bases.

After 27.5 hours, we have submitted 4,962 findings spanning 390 projects, including 85 critical and 635 high-severity issues.

We’re at… pic.twitter.com/iRCylprbY1

— calle (@callebtc) August 5, 2026

While much of the effort continues to be manual, calle noted that the automated systems are improving, with 91% of the findings generated through automated scans. Allowing contributors to utilize their preferred methods of review has proven effective, as diverse prompts yield different vulnerabilities. Approximately 21% of the findings were dynamically reproduced with proof-of-concept code.

The severity of issues varies significantly by category. Privacy and coinjoin tools produced the highest percentage of critical or high-severity findings at 24%, followed by swaps and exchanges at 21%, and payments and merchant tools at 17%. Cryptographic libraries and SDKs accounted for the largest number of total findings at 1,101, although only 10% were classified as high severity.

Challenges for Maintainers

To date, only 19 projects, less than 5% of those examined, have disclosed their findings publicly, indicating that the audit is adding pressure on maintainers. Calle expressed regret if the reports have contributed to their stress, emphasizing the need for rapid dissemination of findings since project owners are best suited to validate them. With AI making validation nearly effortless, others using similar tools are likely to discover the same bugs. Eight findings have already been dismissed as false positives.

Security Concerns in the Bitcoin Ecosystem

This audit comes at a time when Bitcoin's security protocols are facing increased scrutiny. Coinkite's Coldcard wallet users suffered losses exceeding $130 million after a firmware update relied on a software fallback instead of the device’s hardware random number generator, making private keys vulnerable to guessing. In their analysis, the company suggested the possibility that AI was used to analyze earlier firmware versions.

Charles Guillemet, the chief technology officer at Ledger, told Decrypt that this incident highlights how AI is being utilized to identify vulnerabilities in cryptocurrency code at unprecedented speeds. He asserted that "open source and reviewed are not the same," pointing out that the Coldcard vulnerability existed in public code for over five years until an attacker reportedly used AI to exploit it. He further emphasized that defenses must evolve as quickly as the threats they face, as illustrated by the efforts of groups like the Bitcoin Red Team.

Stay Updated with Daily Debrief

Begin each day with the latest news stories alongside original features, podcasts, videos, and more.