Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7
We're running a large-scale ecosystem security audit across bitcoin code bases.
27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.
Much of the work is still manual, "hand holding the AI," calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.
The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.
Maintainers are getting floodedOnly 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.
"We're sincerely sorry if our reports added stress to your already stressful day," he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs. Eight findings have been retired as false positives.
The Coldcard backdrop
















