In brief

  • Cashu creator calle said the campaign logged 85 critical and 635 high-severity issues in its first 30 hours.
  • Contributors each prompt their own agents, which the group says produces a wider spread of hits than a single method would.
  • Privacy and coinjoin projects carried the highest share of serious findings, at 24%.

A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, running what it describes as a “large-scale ecosystem audit” with AI agents doing much of the scanning.

Pseudonymous developer calle, who created the Bitcoin ecash protocol Cashu, published the campaign's first situation report on Wednesday. It puts 85 findings at critical severity and 635 at high, together 14.5% of the corpus and an average of 1.85 serious issues per project, filed at 166 findings an hour. He said the team has grown to 16 people working around the clock; the report logs 17 contributors, 14 of them human and three automated.

Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7

We're running a large-scale ecosystem security audit across bitcoin code bases.

27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.

We're at… pic.twitter.com/iRCylprbY1

— calle (@callebtc) August 5, 2026

Much of the work is still manual, "hand holding the AI," calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.

The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.

Maintainers are getting flooded

Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.

"We're sincerely sorry if our reports added stress to your already stressful day," he wrote, while arguing the findings should go out fast because project owners are best placed to validate them, validation is now nearly free with AI, and anyone else running the same tools will reach the same bugs. Eight findings have been retired as false positives.

The Coldcard backdrop

The campaign lands as Bitcoin's security assumptions come under scrutiny. Coinkite's Coldcard wallet lost users some $130 million after a March 2021 firmware build drew wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable. In a post-mortem, the firm noted it was likely that "someone used AI to review previous versions of our firmware."

Ledger chief technology officer Charles Guillemet told Decrypt on Tuesday that the incident showed AI was now being used to identify vulnerabilities in crypto code "at machine speed." He added that "open source and reviewed are not the same thing," noting the Coldcard flaw sat in public code for more than five years until an adversary reportedly used AI to find it. Defence, he argued, now has to move at the same speed as attackers—as groups like the Bitcoin Red Team are demonstrating.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read full story at Decrypt