Key takeawaysIn 27.5 hours across August 4-5, a 16-person volunteer Bitcoin Red Team filed 4,962 security findings across 390 open-source repositories, including 85 critical and 635 high-severity flaws, all responsibly disclosed to project owners before any public announcement. A 16-person volunteer security team filed 4,962 findings across 390 Bitcoin open-source repositories in 27.5 hours on August 4-5, including 85 critical and 635 high-severity vulnerabilities, per developer Calle's own update on X. The sprint was funded by OpenSats, the U.S. 501(c)(3) nonprofit backing open-source Bitcoin development, which covered roughly $40,000 in AI model token costs. The Coldcard firmware flaw sat in public code from 2021 through 2026, auditable by anyone, examined by almost no one systematically. 85 critical findings.