In brief
- Cashu creator calle said the campaign logged 85 critical and 635 high-severity issues in its first 30 hours.
- Contributors each prompt their own agents, which the group says produces a wider spread of hits than a single method would.
- Privacy and coinjoin projects carried the highest share of serious findings, at 24%.
A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, running what it describes as a “large-scale ecosystem audit” with AI agents doing much of the scanning.
Much of the work is still manual, "hand holding the AI," calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.
The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.
Maintainers are getting flooded
Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.
"We're sincerely sorry if our reports added stress to your already stressful day," he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs. Eight findings have been retired as false positives.
The Coldcard backdrop
The campaign lands as Bitcoin's security assumptions come under scrutiny. Coinkite's Coldcard wallet lost users some $130 million after a March 2021 firmware build drew wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable. In a post-mortem, the firm noted it was likely that "someone used AI to review previous versions of our firmware."
Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the incident showed AI was now being used to identify vulnerabilities in crypto code "at machine speed." He added that "open source and reviewed are not the same thing," noting the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it. Defence, he argued, now has to move at the same speed as attackers—as groups like the Bitcoin Red Team are demonstrating.

