Bitcoin security audit uncovers 4,962 flaws in just 30 hours

In just over a day, a loosely organized band of volunteer coders and their AI assistants did something no single Bitcoin company or developer team could manage alone: they combed through hundreds of open-source Bitcoin projects and flagged nearly 5,000 potential security problems. The effort, run under the name Bitcoin Red Team, has turned into one of the most sweeping Bitcoin security audit campaigns the ecosystem has seen, and it’s forcing an uncomfortable conversation about how exposed the tools people actually use to hold and move bitcoin really are.
Key takeaways
- The Bitcoin Red Team filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, a window some reports put at 27.5 hours.
- Of those findings, 85 were rated critical and 635 high severity, together making up 14.5% of the total.
- The team is made up of 16 globally distributed people plus three automated agents, with 91% of findings surfaced through automated scans.
- Privacy and coinjoin tools carried the highest share of serious issues at 24%, while cryptographic libraries produced the most raw findings (1,101) but a lower 10% high-severity rate.
- Only 19 projects have had their findings reported upstream to maintainers so far.
Inside the Bitcoin Red Team’s Sweeping Security Audit
This is a volunteer-run sprint that pointed AI models at hundreds of Bitcoin codebases at once, something manual code review could never replicate at this pace. The Bitcoin ecash protocol Cashu was developed by pseudonymous creator calle, who released the campaign’s initial status update, describing it as a “large-scale ecosystem security audit” across Bitcoin code bases.
… Continue reading the full article at the original source below.

