After a vulnerability in the RNG of a Coldcard hardware wallet caused losses of over $100 million, the Bitcoin Red Team received more than $40k worth of AI tokens funded by OpenSats to conduct AI-driven security audits of over 390 open-source Bitcoin repositories. According to the report, the 27.5-hour exercise uncovered 85 critical issues and 635 high-severity issues.
Bitcoin Red Team Formed with More Than $40k in OpenSats Funding
Following the Coldcard vulnerability incident, Anchorwatch CEO Rob Hamilton and Bitchat Android developer Calle formed the Bitcoin Red Team. OpenSats, a nonprofit 501(c)(3) organization focused on funding open-source Bitcoin development, covered more than $40k in AI token costs.
The red team includes numerous members of the Bitcoin industry. Those who have publicly expressed support include danielabrozzoni, lylepratt, stutxo, benthecarman, and thesimplekid, among others. The red team currently has no official website or GitHub repository.
27.5-Hour Audit Results: 85 Critical Vulnerabilities and 635 High-Severity Vulnerabilities
In a public report on the security work, Calle stated: “After 27.5 hours of testing, we submitted 4,962 findings across 390 projects, 85 of which were critical issues and 635 of which were high-severity issues. On average, each person submitted 2.31 critical and high-severity issues per hour.”
The red team is actively contacting open-source projects about critical vulnerabilities. This has made industry engineers nervous when they receive direct messages from Hamilton or Calle, and multiple related screenshots have circulated on social media.
AI Model Portfolio: Kimi K3, GPT Sol, Fable, Opus, and GLM5.2
The AI models used by the Bitcoin Red Team during the audit are as follows:
· Kimi K3
· GPT Sol (OpenAI)
· Fable (Anthropic)
· Opus (Claude/Anthropic)
· GLM5.2 (Chinese open-source model)
Initially, limited access to OpenAI and Anthropic models forced the red team to rely heavily on Chinese open-source models, attracting attention across the industry. The red team subsequently established contact with OpenAI and obtained access to GPT Sol. In a post on August 4, Hamilton mentioned Fable, indicating that the team had also obtained access to Anthropic models.
Custom Testing Framework: Planned Open-Sourcing to Allow Bitcoin Companies to Test Closed-Source Code
Hamilton revealed that the red team had built a custom testing framework that at one point contained 171,599 lines of code and was being rapidly iterated. The framework’s functions include identifying and testing critical Bitcoin software libraries and high-load code, identifying and documenting vulnerabilities, reproducing vulnerabilities, and packaging verified data into reports for responsible disclosure to industry engineers.
Hamilton said the plan is to open-source the framework so that Bitcoin companies can use it to test their own closed-source code.
FAQ
What were the specific results of the Bitcoin Red Team’s 27.5-hour audit?
According to Calle’s public report, 4,962 findings were submitted across 390 open-source projects, including 85 critical issues and 635 high-severity issues. Each person submitted an average of 2.31 critical or high-severity findings per hour.
Who covered the Bitcoin Red Team’s audit costs?
According to the article, OpenSats covered more than $40k in AI token costs. OpenSats is a nonprofit 501(c)(3) organization dedicated to funding open-source Bitcoin development projects.
Which AI models did the Bitcoin Red Team use?
According to the article, the models used by the red team included Kimi K3, GPT Sol (OpenAI), Fable (Anthropic), Opus, and GLM5.2. Due to limited access to OpenAI and Anthropic models, the team initially relied heavily on Chinese open-source models, but it has since obtained access to GPT Sol and Fable.