Volunteer developers filed 4,962 security findings across 390 Bitcoin projects in about 30 hours, after the Coldcard vulnerability that allowed predictable seed generation and confirmed thefts of 1,596 BTC — over $100 million. The audit, triggered by that incident, found 85 critical and 635 high-severity issues. Only one of the 391 codebases reviewed came back clean.
The Coldcard trigger
The Coldcard bug let an attacker guess a wallet's seed with just 32 bits of entropy. Confirmed thefts reached 1,596 BTC, and the suspected total is closer to $130 million. The timing isn't great for hardware wallet makers — that category had the second-lowest rate of serious flaws at 9.6%, but the damage was already done.
Korean holders largely escaped because dice-based seeds are common there. That's a small comfort for everyone else.
Where the flaws piled up
Privacy tools had the highest rate of serious issues at 24%, while crypto libraries produced the most findings overall — 1,385 across 128 projects. One hour absorbed 4,101 findings as a backfill, not live scanning. Excluding that, the pace was roughly 29 findings per hour. Not exactly a calm afternoon.
Of all findings, 91% came from automated scanning, and only eight were false positives. About 21.4% included proof-of-concept code. That's a lot of reproducible bugs.
The gap between finding and fixing
Only 147 findings have reached maintainers, and 246 carry no severity label. That's a bottleneck. Rob Hamilton spent over $10,000 scanning 100+ libraries and found multiple serious vulnerabilities on his own — the kind of work that doesn't scale without funding.
OpenSats launched a Code RED grant track to pay researchers who disclose flaws and refund AI-related expenses. It's a start, but the backlog is real.
Market shrugs it off
The Bitcoin market didn't flinch. BTC traded near $64,396, up 0.5% over 24 hours. Active addresses spiked to a 20-month high following the Coldcard incident, though that's more about attention than panic.
This isn't the first weak-randomness bug — the 2023 Milk Sad bug and May's Ill Bloom vulnerability, which drained $5.7 million, both fit the pattern. The difference is scale.
Next up: whether maintainers can triage 4,962 findings before the next exploit. The clock's already ticking.




