Loading market data...

Something like

Something like

. We need to ensure no fabricated quotes. We have Matt Corallo's remark but not the actual quote, so we can paraphrase: "prompting a remark from Bitcoin Core developer Matt Corallo." We can't quote him. So we say "Bitcoin Core developer Matt Corallo noted that only one project came through without a single report." But careful: the fact says "Only one reviewed project reportedly completed the campaign without any reported issues, prompting a remark from Bitcoin Core developer Matt Corallo." So we can say "Only one project came through clean, a result that drew a comment from Bitcoin Core developer Matt Corallo." We don't know what the remark was, so we shouldn't invent. We'll just say it drew a remark. We need to avoid "in the rapidly evolving world" etc. Also, we should mention that researchers have started sending verified critical findings to maintainers. We need to end with a concrete next step: "Researchers are now working through the backlog of verified critical findings, with many maintainers already confirming reports. The next step is to get patches out and retest." Or something like that. Let's write. Word count target 450-700. We'll aim ~550. Let's draft content: Lead: A coordinated Bitcoin security campaign has uncovered nearly 5,000 software issues across hundreds of open-source projects in about 30 hours. The push, which paired 16 human researchers with AI tools, found 85 critical and 635 high-severity flaws. Organizers say verified critical findings are already being sent to project maintainers. Then H2: "How the 30-hour blitz worked" - describe. Then H2: "Where the flaws piled up" - severity and categories. Then H2: "What maintainers are dealing with now" - sending PoCs, confirmations, volume challenge. Then maybe H2: "Why it matters" - context of recent security incidents. But we have that in facts: "The campaign comes as Bitcoin software security receives greater attention across the ecosystem after several recent security incidents." We can use that. We'll have 4 sections. We need to avoid generic headings. Use specific ones. Let's write. Also note: We must not use "in 2024" etc. We can use "this week" or "2026". Today's date is 2026-08-08. So we can say "this week" or "this month" or "on Aug. 6" but we don't know exact date of campaign. We can say "this week" or "in a 30-hour campaign" without date. We'll write in English. Now, let's craft JSON. We need to output only JSON. Ensure proper escaping for HTML. Let's write content. I'll write as a human journalist. Draft:

A coordinated Bitcoin security campaign has uncovered nearly 5,000 software issues across hundreds of open-source projects in about 30 hours. The push, which paired 16 human researchers with AI tools, found 85 critical and 635 high-severity flaws. Verified critical findings are already being sent to project maintainers, organizers said.

Humans and AI, working together

The campaign was led by developer Calle, with backing from OpenSats, OpenCode, and AI inference sponsors. It wasn't a typical audit. Instead of letting automated scanners run wild, human reviewers actively guided the AI systems at every step. Each participant used different prompts and methods, so the tools weren't all probing the same way. That variety helped surface weaknesses a single approach would likely have missed.

Researchers filed 4,962 findings across 390 Bitcoin-related projects. That works out to roughly 166 reports an hour, or about 2.3 critical or high-severity issues for every person-hour spent digging through code.

The breakdown: libraries took the biggest hit

Crypto libraries and software development kits accounted for the largest share, with 1,385 reported issues. About one in every seven findings fell into the high or critical categories. In total, 720 reports were flagged as serious.

Only one reviewed project came through the campaign without a single reported issue — a result that drew a remark from Bitcoin Core developer Matt Corallo.

What happens now

Researchers have started sending verified critical findings to affected maintainers, complete with proof-of-concept retest demonstrations. Many maintainers reportedly confirmed the reports quickly. But processing this volume of findings is a serious challenge, and it's not going to be sorted out overnight.

The campaign comes as Bitcoin software security gets more attention across the ecosystem following several recent security incidents. The work doesn't stop here — the next step is getting fixes out and making sure the retests hold.

That's about 250 words? Let's count. Actually we need 450-700. This is too short. We need to expand with more details from facts. We have many facts. Let's add more. We can add a section on the context of the campaign, maybe "Why this push matters" but we have that. We can elaborate on the process, the difference from traditional audit, the human guidance, the final tally including one contributor's pre-campaign findings. Also mention that the campaign averaged 166 per hour, etc. Also mention that the total included findings collected before the live campaign began. We can add that. Let's expand. Also we can mention that the campaign is a coordinated effort, but we already did. We'll add a paragraph about the methodology: "The final tally even included findings collected by one contributor before the live campaign officially began." That's a detail. We can also mention that the campaign came after several recent security incidents, but we have that. Let's write more. We'll structure: Lead (2-3 sentences) - as above. Section 1: "How the 30-hour hunt was run" - include human guidance, different prompts, pre-campaign findings. Section 2: "The numbers: 4,962 findings, 720 serious" - include breakdown by severity, libraries, 1 in 7, 166/hr, 2.3 per person-hour, only one clean project. Section 3: "From reports to patches" - include sending PoC, maintainers confirming, volume challenge, next steps. Section 4: "Why it matters now" - context of recent incidents, increased attention. That's 4 sections. We'll write each with 2-3 paragraphs. Let's write. Lead: A coordinated Bitcoin security campaign has uncovered nearly 5,000 software issues across hundreds of open-source projects in about 30 hours. The push paired 16 human researchers with AI tools and surfaced 85 critical and 635 high-severity flaws. Verified critical findings are already being sent to project maintainers. Section 1: "How the 30-hour hunt was run" Paragraph: The effort was led by developer Calle, with support from OpenSats, OpenCode, and AI inference sponsors. It wasn't a typical automated audit. Human reviewers actively steered the AI systems at each step, and each participant used different prompts and methods. That spread of approaches helped catch weaknesses a single tool would likely have missed. The final tally even included findings collected by one contributor before the live campaign officially began. Section 2: "The numbers: 4,962 findings, 720 serious" Paragraph: Researchers filed 4,962 findings across 390 Bitcoin-related projects. That's about 166 reports an hour, or roughly 2.3 critical or high-severity issues for every person-hour spent examining code. Crypto libraries and software development kits took the biggest share with 1,385 reported issues. About one in every seven findings landed in the high or critical bucket, and 720 reports were flagged as serious. Only one reviewed project came through without a single reported issue, a result that drew a remark from Bitcoin Core developer Matt Corallo. Section 3: "From reports to patches" Paragraph: Verified critical findings are now being sent to affected maintainers, each with a proof-of-concept retest demonstration. Many maintainers have reportedly confirmed the reports quickly. But the sheer volume is a real bottleneck. Processing nearly 5,000 findings — and turning the serious ones into fixes — will take time. The campaign's organizers haven't said how long they expect that to take, but the retesting work is already underway. Section 4: "Why it matters now" Paragraph: The push lands as Bitcoin software security gets more attention across the ecosystem after several recent security incidents. The hope is that catching these flaws early, before they're exploited, becomes routine rather than reactive. For now, the focus is on getting patches out and making sure the retests hold. That's about 300 words. Still short. We need to add more detail. We can expand section 1 and 2. Also we can add a note about the difference from traditional audit. We have that. We can also mention that the campaign combined human expertise with AI tools. We have that. Maybe we can add a sentence about the severity distribution: "The 720 serious reports include both critical and high-severity issues." But we already. We can also mention that the campaign averaged 166 per hour, but we did. We need to reach 450. Let's add more context about the process: "The campaign was designed to be a stress test of Bitcoin's open-source ecosystem." But that might be invented. We don't have that. We only have facts. So we must stick to facts. We can add a paragraph about the human-AI collaboration: "The approach differed from a traditional security audit because human reviewers actively guided AI systems during testing. Instead of letting the AI run on its own, researchers fed it prompts, steered it toward specific code paths, and interpreted the results in real time." That's from facts. Also we can mention that the campaign brought together 16 researchers. We have. Let's rewrite with more detail. We'll also add a sentence about the fact that the campaign was coordinated, but we have. Let's write a longer version. Lead: A coordinated Bitcoin security campaign has uncovered nearly 5,000 software issues across hundreds of open-source projects in about 30 hours. The push, which paired 16 human researchers with AI tools, found 85 critical and 635 high-severity flaws. Verified critical findings are already being sent to project maintainers, organizers said. Section 1: "How the 30-hour hunt was run" The effort was led by developer Calle, with backing from OpenSats, OpenCode, and AI inference sponsors. It wasn't a typical audit. Instead of letting automated scanners run loose, human reviewers actively guided the AI systems at every stage. Each participant used different prompts and methods, so the tools weren't all probing the same way. That variety helped surface weaknesses a single approach would likely have missed. The final tally even included findings collected by one contributor before the live campaign officially began. That pre-campaign work was folded into the overall count. Section 2: "The numbers: 4,962 findings, 720 serious" Researchers filed 4,962 findings across 390 Bitcoin-related projects. That works out to roughly 166 reports an hour, or about 2.3 critical or high-severity issues for every person-hour spent digging through code. Crypto libraries and software development kits took the biggest share, with 1,385 reported issues. About one in every seven findings landed in the high or critical bucket, and 720 reports were flagged as serious. Only one reviewed project came through without a single reported issue — a result that drew a remark from Bitcoin Core developer Matt Corallo. Section 3: "From reports to patches" Verified critical findings are now being sent to affected maintainers, each with a proof-of-concept retest demonstration. Many maintainers have reportedly confirmed the reports quickly. But the sheer volume is a real bottleneck. Processing nearly 5,000 findings — and turning the serious ones into fixes — will take time. The campaign's organizers haven't said how long they expect the triage to take. What's clear is that the retesting work is already underway, and the backlog is substantial. Section 4: "Why it matters now" The push lands as Bitcoin software security gets more attention across the ecosystem after several recent security incidents. The goal is to catch flaws before they're exploited, and to make that a regular part of how the community operates. For now, the focus is on getting patches out and making sure the retests hold. That's around 330 words. Still short. We need to add more. Maybe we can add a paragraph about the severity distribution: "The 720 serious reports include both critical and high-severity issues. The breakdown: 85 critical, 635 high." We already have that in lead. But we can repeat in section. We can also add a sentence about the campaign's approach being different from a traditional audit. We have. We can also add a note about the fact that researchers are sending verified critical findings, not all findings. We have. Maybe we can add a sentence about the fact that the campaign averaged 166 per hour, but we have. We can also mention that the campaign was a coordinated effort, but we have. Let's see if we can expand section 2 with more detail: "The 720 serious reports include 85 critical and 635 high-severity issues. That's a serious volume for any codebase, and it's spread across hundreds of projects." We can add that. Also we can mention that the campaign ran for about 30 hours, so 166 per hour is a lot. We can add a sentence about the fact that the findings were reported across 390 projects, meaning many projects had multiple issues. We can also add a sentence about the fact that only one project was clean, which is notable. Let's write a final version with more paragraphs. I'll combine. Let's write: Lead: A coordinated Bitcoin security campaign has uncovered nearly 5,000 software issues across hundreds of open-source projects in about 30 hours. The push, which paired 16 human researchers with AI tools, found 85 critical and 635 high-severity flaws. Verified critical findings are already being sent to project maintainers, organizers said. H2: How the 30-hour hunt was run The effort was led by developer Calle, with backing from OpenSats, OpenCode, and AI inference sponsors. It wasn't a typical audit. Instead of letting automated scanners run loose, human reviewers actively guided the AI systems at every stage. Each participant used different