The Bitcoin Red Team, a grassroots security initiative, scanned roughly 390 open-source Bitcoin-related projects and surfaced 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities. The Coldcard exploit that started it allThe Bitcoin Red Team’s audit sprint was a direct response to a firmware vulnerability in Coldcard hardware wallets. That flaw, buried in the device’s random-number generator, led to estimated losses between $70 million and $114 million in stolen Bitcoin. Together they organized the Red Team campaign in late July and early August 2026, assembling volunteers and securing funding from OpenSats, the open-source Bitcoin grant organization. How AI supercharged the auditThe team leaned heavily on open-weight AI models to accelerate the scanning process.