A vulnerability in the Coldcard hardware wallet led to the loss of Bitcoin ($BTC) for long-term holders due to a firmware bug discovered as early as March 2021. Losses exceeded $116 million, with over 1,800 $BTC stolen from more than 5,200 addresses.
This incident served as the catalyst for the creation of a volunteer initiative called 'Bitcoin Red Team,' led by $BTC developer Calle, together with Rob Hamilton, the CEO of the self-custody insurance company Anchorwatch. They conducted an emergency audit of the broader Bitcoin open-source ecosystem to check whether other widely used wallets and code libraries had similar vulnerabilities that led to the loss of Coldcard users' funds.

Sixteen security researchers spent 27.5 hours meticulously analyzing 390 open-source Bitcoin-related repositories, combining AI-assisted analysis with manual review. The team recorded a total of 4,962 vulnerabilities, including 85 classified as critical and 635 as high severity (averaging 2.31 high or critical severity vulnerabilities per researcher per hour).
Funding for this sprint was provided by Opensats—a non-profit organization supporting Bitcoin open-source development—which allocated nearly $40,000 to support the researchers' work. Calle characterized the state of the ecosystem's security as 'extremely poor.'
Analysts monitoring the audit in real-time noted that only about one-fifth of the discovered vulnerabilities had been independently reproduced so far, indicating that many of the identified issues still require confirmation before developers can confidently determine their actual severity.
Where Vulnerabilities Are Concentrated
The highest concentration of severe issues was found in privacy tools and coinjoin software (designed to obfuscate Bitcoin transaction trails on the blockchain), which accounted for 24% of critical findings despite representing a smaller share of the total analyzed projects. Cryptographic libraries, in contrast, yielded the highest absolute number of identified issues—1,101—but a relatively small 10% of those were categorized as high severity, suggesting the code is generally more mature despite being subjected to the most scrutiny from researchers.
The majority of the 390 analyzed projects had few or no critical issues; the real danger appears to be concentrated within a small group of tools responsible for private key generation, signing, and privacy-preserving transactions—the same category of software at the core of the initial Coldcard failure that started this entire effort.
The timing of this disclosure is significant, given that the self-custody Bitcoin user community has spent the last two weeks grappling with the scale of the Coldcard losses, with Canadian users alone accounting for roughly a quarter of the stolen funds.
The Need to Assess Future Challenges
The Bitcoin Red Team noted that the audit is the first phase of ongoing work, not a one-time event; they plan to process the backlog of findings, confirm which vulnerabilities are actually exploitable, and coordinate responsible disclosure with affected projects before any details are made public.
For the self-custody community still coming to terms with the scale of the Coldcard losses, this audit simultaneously serves as proof that 'white hat' researchers are now evolving at a pace approaching that of malicious actors.
end-content







