The Bitcoin Red Team, a volunteer security group, says it found 4,962 vulnerabilities across 390 open-source Bitcoin projects during a 27-hour sweep this week. Eighty-five of those are rated critical. The audit came right after a Coldcard hardware wallet exploit drained bitcoin from long-term holders.
The 27-hour sweep
The team tore through a wide slice of Bitcoin's open-source ecosystem — wallets, node software, libraries, the lot. It's a lot of ground for a volunteer operation. The numbers alone are striking: 4,962 vulnerabilities, 85 of them critical. That works out to roughly a dozen flaws per project on average, though the group didn't say how they're spread.
What the team did say is that the whole audit took a single, marathon stretch. Twenty-seven hours of nonstop checking, from one end of the codebase list to the other. For context, that's barely more than a day of work to comb through nearly four hundred projects.
The Coldcard bug that started it
The sweep followed a Coldcard hardware wallet exploit that siphoned bitcoin from long-term holders. The group's report ties the underlying firmware bug back to March 2021 — meaning it sat in the code for over five years before anyone caught it. That's a long time for a bug that can drain wallets.
The Coldcard incident is still fresh, and the timing of this audit isn't a coincidence. The Red Team appears to have gone looking for similar problems in the wider open-source stack, and they found plenty.
A long list of loose ends
The findings raise a practical question: which of these 390 projects need attention first? The group hasn't published a full list of affected projects or said whether patches are in the works. That leaves a lot of open-source maintainers wondering if their code is on the list.
For a community that runs on trust, this is a lot of loose ends. The Coldcard bug, live since March 2021, is a reminder that even long-standing firmware can hide dangerous flaws. The Red Team's sweep may have turned up the problems, but fixing them is a whole different job.




