The Bitcoin Red Team, which is engaged in security audits of the Bitcoin ecosystem, reported the discovery of 4,962 potential vulnerabilities across nearly 400 projects. Among these, some were assigned a critical severity level, while others were rated high.
The Bitcoin Red Team stated that the team currently consists of 16 specialists working across different time zones in 24/7 mode. According to project participants, they are conducting a large-scale audit of the Bitcoin ecosystem's codebases using a combination of manual review and artificial intelligence-based tools.
According to the team, over a period of 27.5 hours, 4,962 reports on potential vulnerabilities were generated for 390 projects, including:
- 85 critical;
- 635 high-severity.
The Bitcoin Red Team reported that the average rate of work was 2.31 critical or high-severity findings per participant per hour.
The team noted that a significant portion of the audit is still performed manually with AI support, but automated testing systems are gradually becoming more effective. They also emphasized that the different approaches of participants to using AI and crafting prompts allow for more diverse results.
Most critical findings already confirmed by developers
The Bitcoin Red Team stated that they are already in contact with project teams, and most critical reports were promptly confirmed by their developers.
According to the team, before disclosing critical findings, they first verify all the most dangerous issues themselves. To do this, they create a test case and run it on their own computer in a special isolated mode.
At the same time, the initiative's authors acknowledged that the large-scale campaign created additional strain for developers.
"We apologize if our reports added stress to your already busy day. However, we believe it's important to report such findings as quickly as possible, as project owners are best positioned to verify them, and other researchers may soon discover the same issues," said the Bitcoin Red Team.
The team also noted that they continue to improve the process of verifying discovered vulnerabilities and are working on reducing the number of irrelevant reports.
Recall that in April 2026, the Ethereum Foundation summarized the results of the ETH Rangers program. As a result, 17 researchers recovered $5.8 million and found 785 vulnerabilities.
end-content






