Volunteer developers filed 4,962 security findings across 390 Bitcoin projects in about 30 hours. Of the 391 codebases they reviewed, exactly one came back clean.
The group calls itself the Bitcoin Red Team. It rated 720 of those findings high or critical. Only 147 have reached the maintainers who have to fix them.
Every 1 in 7 Findings is Serious
The severity split is narrower than the raw total suggests. Reviewers logged 85 critical issues and 635 high ones.
That works out to 14.5% of everything filed. The rest sit in medium, low, or informational buckets. Another 246 findings carry no severity label at all.
Evidence quality varies too. About 21.4% came with working proof-of-concept code. Roughly 91% arrived through automated scanning. Reviewers retired just eight as false positives.
Follow us on X to get the latest news as it happens
One Hour Produced 83% of the Findings
The 30-hour framing needs a caveat. A single hour absorbed 4,101 findings. That spike was a backfill, not live scanning. Rob Hamilton, chief executive of Bitcoin insurer AnchorWatch, ran his own review before the campaign formally began.
He said he spent over $10,000 scanning more than 100 libraries.
Strip the dump out, and the pace changes sharply. Roughly 840 findings were received over the other 29 hours. That is closer to 29 an hour than the 166.3 the report advertises.
The Data Points Away From Hardware Wallets
The category breakdown carries a surprise. Hardware wallets and firmware, the group Coldcard belongs to, ranked second lowest for serious flaws at 9.6%.
Other corners fared worse. Mining pools hit 21.7%, infrastructure and tooling 21.5%, and swaps and exchanges 20.9%. Privacy tools topped the table at 24%, though reviewers covered only three of them.
Crypto libraries carried the volume instead. They produced 1,385 findings across 128 projects, more than a quarter of the corpus.
Calle, the pseudonymous physicist who created the Cashu ecash protocol, said maintainers are confirming the worst reports.
Most of the critical reports we’ve made so far were quickly verified by project owners. We know we’re hitting real targets,” they wrote.
Why the Red Team Formed After Coldcard
The sweep began because of one broken chip. Coinkite disclosed on July 30 that seed generation on affected Coldcard devices fell back to a predictable software routine.
The shortfall was severe. Only 32 bits came from the secure element, capping an attacker’s search at about 4.3 billion guesses.
Galaxy Research pegged confirmed thefts at 1,596 Bitcoin (BTC) from roughly 7,300 addresses on Aug. 4. A suspected fourth attack wave would bring the total to nearly $130 million. Galaxy stresses its address list is not definitive.
The panic showed up on-chain, where active addresses spiked to a 20-month high. Korean holders largely escaped because dice-based seeds are common there.
Weak randomness keeps returning in Bitcoin, however. The 2023 Milk Sad bug seeded Libbitcoin Explorer keys from 32 bits of clock time. In May, the Ill Bloom vulnerability drained $5.7 million from wallets built on a weak JavaScript generator.
Funding Follows the Findings
OpenSats, a nonprofit that funds Bitcoin development, launched a Code RED grant track on Thursday. It pays researchers who disclose flaws. It also refunds the artificial intelligence (AI) bills the work runs up.
Meanwhile, Bitcoin traded near $64,396 on Thursday, up 0.5% over 24 hours. The audit has not moved the market.
Context still matters for the raw number. These are findings, not confirmed exploits, and most will never be weaponized.
On the evidence so far, though, Coldcard was not an isolated failure. The data also suggests the next one will not be a hardware wallet.
The post Bitcoin Network Warning: Developers Find Nearly 5,000 Vulnerabilities appeared first on BeInCrypto.
Security,Bitcoin (BTC) News,Editor’s Pick,Security (Crypto Scams and Hacks),Wallet Security#Bitcoin #Network #Warning #Developers #Find #Vulnerabilities1786052858

