Bitcoin's AI red team found 85 critical bugs in about a day
Nearly 5,000 Findings in Under 28 Hours A volunteer security initiative known as the Bitcoin Red Team has completed one of the most sweeping audits the Bitcoin ecosystem has seen. Led by Anch
A
AnonymousCryptoCompass newsroom
August 6, 2026
2 min read
NEWS
CryptoCompass editorial visual for bitcoin coverage.
Nearly 5,000 Findings in Under 28 Hours
A volunteer security initiative known as the Bitcoin Red Team has completed one of the most sweeping audits the Bitcoin ecosystem has seen. Led by AnchorWatch CEO Rob Hamilton (@Rob1Ham) and Bitchat developer Calle (@callebtc), the group uncovered 4,962 security issues across 390 open-source projects during a 27.5-hour sprint on August 4 and 5, 2026.Of those findings, 85 were classified as critical and 635 as high-severity, averaging 166 findings per hour.
The team has grown to 16 globally distributed researchers working around the clock. While AI tools powered much of the throughput, the researchers noted that much of the work still involves manually guiding the AI, even as their automated harnesses continue to improve.Most of the critical reports filed so far were quickly verified by project owners, confirming the team is identifying real vulnerabilities.
Sparked by the Coldcard RNG Exploit
The audit was a direct response to a serious security breach affecting Coldcard hardware wallets. A vulnerability introduced in Coldcard firmware 4.0.0 in March 2021 caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by non-secret chip data.An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.Total losses have since climbed to more than $130 million, according to blockchain-monitoring firms.
Canada-based Coinkite, whose affected Coldcard wallets were drained, warned that the vulnerability "is a warning for every company building Bitcoin hardware and software, not only us." That warning appears to have galvanized the broader developer community into action.
Funding for the Red Team effort came from OpenSats (@OpenSats), a nonprofit that supports open-source Bitcoin development, which contributed nearly $40,000 to cover AI compute costs. The team is now planning to open-source the tools it built during the sprint, enabling other Bitcoin companies to run ongoing audits of their own codebases. The goal is to let projects scan their own closed-source code before attackers do.
Binance is reportedly preparing to seek FCA authorization as part of a potential UK relaunch, a move that would mark a formal attempt by the world's largest crypto exchange to re-establish re
Jane Street Group’s newest 13F filing, covering the quarter that ended June 30, 2026, shows the firm still held shares of BlackRock’s iShares Bitcoin Trust and Fidelity’s Wise Origin Bitcoin
Some charts move so fast that even people watching full-time have to double-check the decimal point. That's roughly what happened with a small education-focused token this week, and it's why