Bitcoin Red Team Uncovers 85 Critical Bugs Across 390 Open Source Projects
A security initiative known as the Bitcoin Red Team has flagged 85 critical vulnerabilities among nearly 5,000 findings across 390 open-source software repositories used in the cryptocurrency ecosystem. The effort, led by researchers Calle and Rob Hamilton, was prompted by a vulnerability in the Coldcard hardware wallet's random number generator (RNG), which attackers exploited to drain more than $100 million from affected users.
Using frontier AI models to accelerate code review, the team has been systematically auditing widely used open-source projects that underpin Bitcoin infrastructure, from wallets to supporting libraries. The scale of the findings highlights a broader concern: much of the software securing digital assets is maintained by small teams or volunteers, and flaws can go undetected for years before being exploited.
While this initiative centres on cryptocurrency software, it offers a useful reminder for any business relying on open-source components, which is now the vast majority. Vulnerabilities in shared code libraries can quietly affect thousands of downstream products, making regular audits and prompt patching essential rather than optional.