A Sixteen-Person AI Audit Returns 4,962 Findings Across 390 Bitcoin Repos

Over 27.5 hours on 4 and 5 August 2026, a group of sixteen volunteer security researchers calling itself the Bitcoin Red Team filed 4,962 findings across 390 open-source repositories, by the accounts published on 5 August. Of those, 85 were rated critical and 635 high severity. The software engineer Calle and Rob Hamilton, chief executive of Anchorwatch, organized the run, and OpenSats put up just over $40,000 to cover tokens for the commercial AI models that did the scanning. The team said it would open-source the custom harness that drove them, a codebase of 171,599 lines. The trigger, the organizers said, was the Coldcard exploit.
4,962 findings at 180 an hour
The sprint's arithmetic was published alongside the totals. Across 27.5 hours the group averaged 180 findings an hour collectively, or 2.31 findings per researcher per hour, a throughput that describes machine scanning with human review rather than manual code reading. "27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues," the team said. The headline numbers were:
- 4,962 findings across 390 open-source repositories
- 85 rated critical, 635 rated high severity
- 27.5 hours of elapsed run time, 16 volunteer researchers
- Just over $40,000 of OpenSats funding, spent on AI tokens
Five models behind one harness
The models named by the team were Kimi K3, GPT Sol, Fable, Opus and GLM5.2, driven through a single harness the group wrote for the purpose. The harness is the orchestration layer that feeds code to a model, collects its output and routes it for triage, and it is the artifact the team said it would release publicly. It is the part with consequences beyond this sprint. Findings went out under responsible disclosure, meaning private reproduction first, then notification to maintainers. A caution belongs next to the headline figures: the published counts are severity ratings assigned during the run, not a tally of demonstrated exploits. The team did not call the sprint an incident.
Ecosystem tooling, not the core protocol
Bitcoin's core protocol was not audited. The 390 repositories were the surrounding tooling and applications, the wallets, libraries, services and plumbing that sit between users and the chain, not the consensus code in Bitcoin Core. Most of that surface is maintained by volunteers or very small teams, and that was the point the exercise was built to make: the code with the least maintainer capacity is also the code an automated scanner covers fastest. The choice of scope also means the sprint says nothing about consensus-layer risk. The organizers did not claim otherwise.
The same tooling on both sides
The summer's security news has run the other way. The Coldcard firmware flaw put more than $100 million of bitcoin in attackers' hands, and on 4 August the non-custodial swap service Boltz suspended its Bitcoin bridge indefinitely, saying attackers now iterate faster than a team its size can find and patch vulnerabilities. The Red Team sprint is the first sizeable demonstration of the defender-side version of the same capability. Releasing the harness puts it in the hands of maintainers and of anyone else who wants it. What happens now depends on the receiving end: 4,962 findings landed on projects that are mostly volunteer-run, and no timetable had been published for triaging them, or for the release of the harness itself, at the time of writing.
Read also: Galaxy Counts at Least Fifteen Attackers in the Coldcard Exploit