A volunteer group called the Bitcoin Red Team has executed what appears to be the crypto ecosystem’s most aggressive security sweep to date, filing nearly 5,000 vulnerability reports across 390 Bitcoin projects in just 30 hours using AI-assisted scanning. The campaign highlights both the potential and the peril of machine-powered code review—revealing serious gaps in widely used software while simultaneously raising uncomfortable questions about whether open-source maintainers can keep pace with automated threat detection.

As first reported by Decrypt, the group filed 4,962 total findings, including 85 flagged as critical severity and 635 as high. That works out to an average of 1.85 serious issues per project and a filing rate of 166 findings per hour. Pseudonymous developer calle, creator of the Bitcoin ecash protocol Cashu, published the campaign’s initial status report on August 5, noting the team had grown to 16 contributors working around the clock.

The AI Advantage—And Its Limits

What distinguishes the Bitcoin Red Team’s approach is its deliberate reliance on different AI methodologies rather than a single scanning tool. Contributors deploy their own preferred AI agents with custom prompts, a strategy calle credits with uncovering a wider range of vulnerabilities than any monolithic approach could achieve. Roughly 91% of findings came through automated intake, though calle acknowledged much work remained “hand holding the AI” through edge cases.

The strategy appears sound. Only around 21% of findings have been reproduced with proof-of-concept code so far, suggesting many may be false positives or require further validation. Eight have already been retired. Yet the sheer volume—filing at machine speed—has already stressed an ecosystem ill-equipped to absorb thousands of concurrent disclosures.

Vulnerability Distribution Reveals Weak Spots

The severity picture varies dramatically by project category. Privacy and coinjoin tools carried the highest concentration of serious issues, with 24% of findings rated high or critical. Swaps and exchanges followed at 21%, with payments and merchant tools at 17%. Cryptographic libraries and SDKs, by contrast, generated the largest raw volume at 1,101 findings but only cleared the high-severity threshold in 10% of cases—suggesting mature, well-tested code in those domains.

Only 19 projects—under 5%—had findings disclosed to maintainers by early August, reflecting both the recency of the audit and the organizational challenge of coordinated disclosure at this scale.

The Coldcard Precedent

The Bitcoin Red Team’s campaign arrives against a chastening backdrop. Coinkite’s Coldcard hardware wallet lost users approximately $130 million after a March 2021 firmware version drew wallet seeds from a software fallback rather than the device’s hardware random number generator, rendering private keys predictable. In a post-mortem, Coinkite noted the flaw sat in publicly available code for more than five years before an adversary reportedly used AI to uncover it.

Ledger’s Chief Technology Officer Charles Guillemet told Decrypt the Coldcard incident underscored a hard truth: defenders now face threats at “machine speed.” The vulnerability persisted in plain sight because, as Guillemet emphasized, “open source and reviewed are not the same thing.” The implication is stark. Attackers have access to the same AI tools volunteers like the Bitcoin Red Team are now deploying, and they have strong financial incentives to find exploitable flaws first.

A Difficult Moment for Maintainers

Calle acknowledged the campaign’s timing created stress for already-stretched project maintainers, issuing a formal apology for adding to their burden. Yet he argued for rapid disclosure, contending that project owners are best positioned to validate findings and that AI now makes validation nearly cost-free. Anyone else running identical tools will reach the same conclusions anyway, he reasoned, so speed matters more than gatekeeping.

The tension is real. An audit of this scale and speed reveals genuine security work. It also reveals the precarity of Bitcoin’s open-source infrastructure—a network worth hundreds of billions in market value, defended by volunteers with finite time and resources. The Bitcoin Red Team’s campaign suggests that asymmetry is no longer sustainable.