In the wake of a major security flaw that compromised thousands of Coldcard hardware wallets, a volunteer coalition of developers and researchers known as the Bitcoin Red Team launched a sweeping, ecosystem-wide security review. Organized by open-source developer Calle and AnchorWatch CEO Rob Hamilton, the initiative uses custom AI-powered testing harnesses combined with manual verification to inspect critical Bitcoin libraries, wallet software, and core infrastructure code.
During its initial 29.8 hours of active scanning, the team reviewed 390 open-source repositories and identified 4,962 potential software issues. Within that total, the audit flagged 720 findings classified as high or critical severity. The researchers confirmed that 21.4% of all reported issues have already been independently reproduced and verified. Calle publicly described the rapid rate of discovery as averaging roughly one critical exploit per person per hour, highlighting widespread technical vulnerabilities across legacy and active Bitcoin projects.
Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7
We're running a large-scale ecosystem security audit across bitcoin code bases.
27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.
We're at… pic.twitter.com/iRCylprbY1
— calle (@callebtc) August 5, 2026
To maintain continuous testing, the initiative incurs approximately $10,000 per day in compute costs, funded in part by open-source grant organization OpenSats. AI infrastructure support has been provided by Kimi Moonshot via its Kimi K3 model, alongside allocations from OpenAI and Anthropic. To prevent exploitation, the team is privately disclosing verified critical bugs directly to maintainers rather than making immediate public releases.
Fallout From the Coldcard Firmware Entropy Flaw
The emergency security blitz follows one of the most severe self-custody exploits in Bitcoin’s history. Attacks stemmed from a deterministic pseudo-random number generator (PRNG) flaw in Coldcard hardware wallet firmware produced by Coinkite. Traced to a March 2021 code update during a cryptographic library migration, the vulnerable builds bypassed the device’s physical STM32 hardware random number generator, relying instead on MicroPython’s fallback generator initialized from static chip IDs and timer registers.
This fallback severely degraded key entropy, reducing 12-word seed security from 128 bits down to roughly 40 bits on Mk2 and Mk3 models, and approximately 72 bits on Mk4, Mk5, and Q devices. The reduced search space allowed attackers to precompute candidate private keys offline and sweep funds across multi-wave automated transactions, stealing upwards of 1,596 to 2,055 BTC from thousands of affected addresses.
Coinkite released emergency patched firmware for all affected models; however, developers warned that updating the software does not fix existing seed phrases generated on compromised builds. Users must generate entirely new seeds on updated firmware and transfer funds to clean addresses to secure their assets. As multi-agency investigations proceed, the Bitcoin Red Team plans to open-source its automated auditing framework to allow developers across the industry to continuously test their software against emerging AI-driven exploit vectors.
Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.