Bitcoin Network Warning: Developers Find Nearly 5,000 Vulnerabilities
- Volunteer developers filed 4,962 security findings across 390 Bitcoin projects in about 30 hours.
- Of the 391 codebases they reviewed, exactly one came back clean.
- Only 147 have reached the maintainers who have to fix them.
- The severity split is narrower than the raw total suggests.
What Happened
Volunteer developers filed 4,962 security findings across 390 Bitcoin projects in about 30 hours. Of the 391 codebases they reviewed, exactly one came back clean.
That works out to 14.5% of everything filed. The rest sit in medium, low, or informational buckets. Another 246 findings carry no severity label at all.
Market Context
Crypto libraries carried the volume instead. They produced 1,385 findings across 128 projects, more than a quarter of the corpus.
The shortfall was severe. Only 32 bits came from the secure element, capping an attacker’s search at about 4.3 billion guesses.
The panic showed up on-chain, where active addresses spiked to a 20-month high. Korean holders largely escaped because dice-based seeds are common there.
Why It Matters
The severity split is narrower than the raw total suggests. Reviewers logged 85 critical issues and 635 high ones.
Weak randomness keeps returning in Bitcoin, however. The 2023 Milk Sad bug seeded Libbitcoin Explorer keys from 32 bits of clock time. In May, the Ill Bloom vulnerability drained $5.7 million from wallets built on a weak JavaScript generator.
Details
The group calls itself the Bitcoin Red Team. It rated 720 of those findings high or critical. Only 147 have reached the maintainers who have to fix them.
Every 1 in 7 Findings is Serious
Evidence quality varies too. About 21.4% came with working proof-of-concept code. Roughly 91% arrived through automated scanning. Reviewers retired just eight as false positives.
Follow us on X to get the latest news as it happens
One Hour Produced 83% of the Findings
The 30-hour framing needs a caveat. A single hour absorbed 4,101 findings. That spike was a backfill, not live scanning. Rob Hamilton, chief executive of Bitcoin insurer AnchorWatch, ran his own review before the campaign formally began.
He said he spent over $10,000 scanning more than 100 libraries.
Strip the dump out, and the pace changes sharply. Roughly 840 findings were received over the other 29 hours. That is closer to 29 an hour than the 166.3 the report advertises.
The Data Points Away From Hardware Wallets
The category breakdown carries a surprise. Hardware wallets and firmware, the group Coldcard belongs to, ranked second lowest for serious flaws at 9.6%.
Other corners fared worse. Mining pools hit 21.7%, infrastructure and tooling 21.5%, and swaps and exchanges 20.9%. Privacy tools topped the table at 24%, though reviewers covered only three of them.
Calle, the pseudonymous physicist who created the Cashu ecash protocol, said maintainers are confirming the worst reports.
Most of the critical reports we’ve made so far were quickly verified by project owners. We know we’re hitting real targets,” they wrote.
Why the Red Team Formed After Coldcard
The sweep began because of one broken chip. Coinkite disclosed on July 30 that seed generation on affected Coldcard devices fell back to a predictable software routine.
Galaxy Research pegged confirmed thefts at 1,596 Bitcoin (BTC) from roughly 7,300 addresses on Aug. 4. A suspected fourth attack wave would bring the total to nearly $130 million. Galaxy stresses its address list is not definitive.
Funding Follows the Findings