Volunteer Hackers Uncover Nearly 5,000 Flaws in Bitcoin Software After Wallet Hack
A volunteer security group known as the Bitcoin Red Team has identified 4,962 vulnerabilities, including 85 rated critical, across 390 open-source Bitcoin projects during an intensive 27-hour review. The effort was launched in direct response to a security incident involving the Coldcard hardware wallet, which was exploited to drain bitcoin from long-term holders.
The Coldcard exploit reportedly stemmed from a firmware bug that had existed since March 2021, meaning the flaw went undetected for years before attackers took advantage of it. The scale and speed of the Bitcoin Red Team's findings highlight how widespread security weaknesses can be in software that underpins financial infrastructure, even when that software is open source and subject to community review.
While this incident centres on cryptocurrency hardware and software, it underscores a broader lesson for any business relying on third-party or open-source tools: long-standing, unpatched vulnerabilities can sit undetected for years and be exploited without warning. Businesses that use hardware wallets, financial software, or other security-critical tools should stay alert to vendor advisories and firmware updates.