Skip to main content

Bitcoin Red Team Finds 4,962 Flaws After Coldcard Hack

Importance High

A volunteer security group called the Bitcoin Red Team uncovered 4,962 vulnerabilities, 85 of them critical, across 390 open-source Bitcoin projects over a 27-hour stretch after the Coldcard hack.

The audit was a response to the Coldcard hardware wallet exploit, which drained bitcoin from long-term holders due to a firmware bug dating to March 2021. Losses have climbed past $116 million across more than 1,800 BTC from over 5,200 addresses.

Led by Bitcoin developer Calle and Rob Hamilton, CEO of self-custody insurer Anchorwatch, the team of 16 security researchers spent 27.5 hours combing through repositories, combining AI-assisted analysis with manual review. They filed 4,962 total security findings, including 85 critical and 635 high-severity — a pace averaging 2.31 high- or critical-severity findings per researcher per hour.

Funding for the sprint came from Opensats, a nonprofit that backs open-source Bitcoin development, contributing close to $40,000. Calle described the state of ecosystem security as “extremely bad.”

Analysts noted that only about one in five findings had been independently reproduced, indicating many flagged issues still need confirmation before developers can assess real-world severity.

Where the Flaws Are Concentrated

Privacy and coinjoin tools accounted for the highest concentration of serious issues, representing 24% of critical findings despite making up a smaller share of total projects. Cryptographic libraries generated the largest raw number of findings (1,101) but a comparatively low 10% high-severity rate, suggesting that code is generally more mature.

Most of the 390 projects had few or no critical issues; the real danger was concentrated in tools handling private key generation, signing, and privacy-preserving transactions — the same category at the root of the Coldcard failure.

The Future Needs Assessing

The Bitcoin Red Team noted that the audit is the first phase of an ongoing effort, with plans to work through the backlog, confirm exploitable vulnerabilities, and coordinate responsible disclosure with affected projects before public details are released.

For a self-custody culture still absorbing the size of the Coldcard losses, the audit doubles as evidence that white-hat researchers are now moving at a pace closer to that of attackers.

Source: https://news.bitcoin.com/security/bitcoin-red-team-audit-coldcard-vulnerabilities/