Bitcoin Red Team Reports 85 Critical Flaws

BTC

BTC/USDT

$64,701.06
+0.76%
24h Volume

$15,055,494,104.69

24h H/L

$65,025.22 / $63,880.00

Change: $1,145.22 (1.79%)

Long/Short
54.6%
Long: 54.6%Short: 45.4%
Funding Rate

+0.0018%

Longs pay

Data provided by COINOTAG DATALive data
Bitcoin
Bitcoin
Daily

$64,703.98

0.93%

Volume (24h): -

Resistance Levels
Resistance 3$72,666.77
Resistance 2$70,242.31
Resistance 1$65,409.56
Price$64,703.98
Support 1$64,390.56
Support 2$63,367.25
Support 3$61,044.16
Pivot (PP):$63,992.58
Trend:Sideways
RSI (14):53.4
(10:06 PM UTC)
4 min read
AI SummaryAI
  • The Bitcoin Red Team filed 4,962 findings across 390 open-source repositories, including 85 critical issues.
  • OpenSats covered more than $40,000 in AI-token costs for the Bitcoin code review.
  • Galaxy Digital's Alex Thorn said Coldcard losses exceeded $100 million, around 1,600 BTC before a fourth wave.
  • Three confirmed Coldcard sweeps involved roughly 1,367 BTC and 4,585 addresses in total.

Bitcoin News

Bitcoin (BTC) developers have organized a rapid security response after the Coldcard wallet exploit exposed weaknesses in self-custody infrastructure. The volunteer effort, known as the Bitcoin Red Team and coordinated by Calle and Rob Hamilton, says it has filed 4,962 findings across 390 open-source repositories. The tally includes 85 critical issues and 635 high-severity findings, recorded after roughly 27.5 hours of review. More than $40,000 in AI-token costs, covered by OpenSats, has supported the scan of code using frontier models, including Kimi K3, GPT Sol, Fable, Opus and GLM5.2. The group describes a custom harness, at one point containing 171,599 lines of code, that identifies important libraries, reproduces suspected vulnerabilities and packages evidence for responsible disclosure. Unlike an AI trading bot that reacts to market data, this tool is aimed at security-critical paths. The team also plans to release the harness so companies can test closed-source implementations, extending the post-Coldcard review beyond public Bitcoin repositories. Early model access was uneven, with Chinese open-source systems filling the gap before OpenAI and Anthropic channels became available. Hamilton has said the project benefits when engineers add niche context, allowing the harness to confirm issues that automated scans can smell but not fully classify.

The exploit that triggered the audit push has already produced one of the largest self-custody thefts on record. Galaxy Digital research head Alex Thorn said the Coldcard vulnerability drained well over $100 million in BTC, with losses around 1,600 BTC even before a suspected fourth wave was added. Three confirmed sweeps accounted for about 1,367 BTC, roughly $89 million, and touched approximately 4,585 addresses. A fourth pattern, flagged on Aug. 3, moved hundreds of additional coins through a burst of blocks at about 45 times the normal rate, lifting the combined estimate to around 1,815 BTC, or near $114 million, across about 5,294 addresses. Thorn also identified roughly 14 more attacker patterns not yet included in the public tally and stressed that victims “did nothing wrong.” The average stolen coin had remained untouched for nearly four years, pointing to long-term holders rather than active traders. Coinkite, Coldcard’s maker, has apologized and shipped corrected firmware, while advising users to move funds from single-signature addresses created with vulnerable software. Some victims may still recover coins if unconfirmed transactions support replace-by-fee, but the window is narrow and depends on rapid action. Thorn placed the fourth wave in the medium-to-high confidence range and urged victims to file reports with the FBI’s IC3 and local police, while preserving the compromised device as evidence.

The most detailed post-mortem traces the failure to a March 17, 2021 code migration that changed how Coldcard generated wallet seeds. During the move to libsecp256k1 and the embedded libNgU library, seed generation was rerouted from a hardware random-number path to a predictable software generator because a compile-time macro was checked only for presence, not value. The device continued to produce normal-looking recovery phrases, so the weakness remained hidden for years. Coinkite’s official advisory and related technical analysis estimate the effective search space at about 40 bits for affected Mk2 and Mk3 seeds, while Mk4, Mk5 and Q devices received only limited extra entropy, leaving roughly 72 bits instead of the intended 128-bit target. The advisory lists specific vulnerable firmware branches and fixed releases, including 4.2.0 for Mk2/Mk3, 5.6.0 for standard Mk4/Mk5, 1.5.0Q for Q, and 6.6.0X or 6.6.0QX for Edge builds. The first major sweep began July 30, when about 500 addresses were emptied in roughly 25 minutes before the total observed scope expanded. Crucially, updating firmware does not repair an old phrase. Users must generate a new seed on patched firmware or another trusted environment and send funds to the new addresses. On-chain sweeps showed automated behavior, including many fixed-fee transactions without change outputs, but the incident did not break Bitcoin cryptography itself.

COINOTAG’s analysis is that these developments form one lesson: the Coldcard event is an implementation failure, not a Bitcoin protocol failure. The on-chain record — repeated sweep patterns, fixed-fee transactions, RBF-enabled transfers and an estimated 1,815 BTC drain — provides verifiable evidence of automated exploitation. Coinkite’s own advisory identifies the root cause as a weak seed-generation path and sets the remediation: create a new seed on fixed firmware and migrate funds. For users of any future AI crypto wallet, the takeaway is that key generation must be independently auditable. The stolen coins were largely old, outlasting a full bear market, which makes the operational failure more painful but does not invalidate self-custody when properly implemented.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Michael Roberts

Michael Roberts

COINOTAG author

View all posts
AI-AssistedCrypto Research Analyst·Michael Roberts is a crypto research analyst focused on blockchain technology, decentralized finance (DeFi), and Web3 ecosystem developments.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments