+0.90%
+0.50%
+2.90%
+0.20%
-4.80%
-1.50%
How the Audit Happened
Led by BTC developer Calle and Anchorwatch CEO Rob Hamilton, the Bitcoin Red Team combined AI tools with manual code review to scan 390 open-source Bitcoin repositories. The pace was aggressive: 2.31 high or critical findings per researcher per hour.
The audit was funded by Opensats, a nonprofit supporting open-source Bitcoin development, with nearly $40,000 in backing. The findings break down like this:
- 4,962 total security flaws identified
- 85 critical severity issues
- 635 high-severity flaws
- 390 projects audited
- 27.5 hours total time
What Triggered the Urgency
A recent Coldcard hardware wallet exploit made this audit urgent. The firmware bug, present since March 2021, allowed attackers to drain over $116 million in Bitcoin from long-term holders. More than 1,800 BTC were pulled from over 5,200 addresses.
The Red Team’s core question was straightforward: If Coldcard had this vulnerability, what else was broken? This was a proactive move to prevent further catastrophic losses in the self-custody community.
Privacy Tools Are the Weakest Link
The audit revealed something concerning: vulnerability severity wasn’t evenly distributed. Privacy and coinjoin tools, designed to obscure Bitcoin transaction trails, accounted for 24 percent of all critical findings despite representing a smaller share of reviewed projects.
By contrast, cryptographic libraries generated the most findings at 1,101, but only 10 percent were high-severity. This suggests foundational code bases are more mature. The real danger lies in software handling private key generation, signing, and privacy-preserving transactions.
The Severity Problem
Here’s where it gets complicated: Calle described the current state of ecosystem security as extremely bad
. But analysts noted that only about one in five findings had been independently reproduced. This means many flagged issues still need confirmation of whether they’re actually exploitable in the real world.
The timing stings. Bitcoin’s self-custody community has spent weeks absorbing the scale of Coldcard losses. Canadian users alone accounted for roughly a quarter of the stolen funds.
What Happens Next
The Bitcoin Red Team views this audit as phase one of an ongoing effort. They plan to work through the backlog of findings, confirming exploitable vulnerabilities and coordinating responsible disclosure with affected projects. Details will remain private until developers can patch the issues.
This audit demonstrates that white-hat researchers are now operating at a pace closer to that of attackers. But there’s a catch: the attacker behind the Coldcard exploit still holds approximately 2,055 BTC, valued at about $130 million, and hasn’t moved the funds.
The Red Team’s work shows both promise and peril. Security researchers are catching flaws faster than ever. But with 4 out of 5 findings still unconfirmed, the ecosystem still has a long way to go before self-custody becomes truly safe.
Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates



