A volunteer security initiative named Bitcoin Red Team, led by developer Calle and AnchorWatch CEO Rob Hamilton, has uncovered 85 critical and 635 high-severity vulnerabilities across 390 open-source Bitcoin repositories within the first 27.5 hours of a massive AI-assisted audit. The effort, detailed by Bitcoin Magazine on August 5, 2026, filed a total of 4,962 findings while covering 171,599 lines of code with a globally distributed team of 16 researchers working around the clock.
Funded by over $40,000 in AI compute costs covered by nonprofit OpenSats, the project was triggered by a critical random number generator (RNG) vulnerability in Coldcard MK3+ hardware wallets that already resulted in more than $100 million in confirmed Bitcoin losses, exploited by at least 15 attackers according to Galaxy Research. The team deployed AI models including Kimi K3, GPT Sol, Fable, Opus, and GLM5.2, averaging roughly one critical exploit per person per hour—a pace Calle described as indicating the situation is extremely bad. Early restrictions on OpenAI and Anthropic access forced reliance on Chinese open-source models, a point noted by industry observers as a sign of uneven U.S. AI access.
Hamilton confirmed that OpenAI and Anthropic have since granted access, and plans are in place to open-source the audit harness so Bitcoin companies can test closed-source codebases. The immediate fallout already includes Boltz exchange pausing operations to address AI-discovered vulnerabilities, illustrating the audit’s swift, industry-wide pressure. Maintainers now face the task of reproducing, prioritizing, and patching flaws while preventing premature exposure of exploitable details.