Morning Edition · Thursday, August 6, 2026Published at 1:33 AM EDT · New York
Bitcoin Red Team Files 4,962 Security Findings Across 390 Projects After Coldcard Theft
The volunteer group reported 85 critical and 635 high-severity issues in about 27 hours, while on-chain investigators tracked laundering of coins taken through the wallet flaw.

Sixteen volunteer researchers working as the Bitcoin Red Team, organized by the developer known as Calle and by Rob Hamilton, chief executive of the custody firm AnchorWatch, filed 4,962 security findings across 390 open-source Bitcoin projects during a sprint on 4 and 5 August. The group classified 85 findings as critical and 635 as high severity. It used artificial-intelligence analysis harnesses to read wallet code, cryptographic libraries and node infrastructure faster than manual review allows, and it worked on a $40,000 grant from the funding organization OpenSats. Calle wrote publicly that the team was averaging roughly one critical exploit per researcher per hour.
The sprint followed the Coldcard incident. A firmware integration error shipped in March 2021 sent seed generation on some devices to a deterministic software pseudorandom number generator instead of the hardware random number generator on the device's STM32 chip. The private keys those devices produced were therefore reproducible. Galaxy Research has traced three rounds of thefts totalling about 1,367 bitcoin, close to $89 million at recent prices, from roughly 4,585 addresses.
Most of the stolen coin has not moved. Galaxy said the single largest theft, 1,159 bitcoin, remains untouched, while a separate attacker has begun routing smaller sums through a mixing service, starting with about 10 of 64 bitcoin sent. Investigators have circulated roughly 600 flagged addresses to exchanges, analytics firms and law enforcement.
The commercial assessment came quickly. Analysts at Cantor and FRNT told CoinDesk the breach could push some holders toward regulated custodians and exchange-traded funds. Bitcoin Magazine's editorial argues the opposite, that the failure was one vendor's build process, not self-custody itself. Both conclusions can hold at once. The defect was an implementation error in a certified device, and the practical response for many holders is to pay someone else to hold their keys.
- If true, who benefits
Regulated custodians, bitcoin exchange-traded fund issuers and security vendors gain from a self-custody failure, and Galaxy, which both published the forensic count and sells institutional custody and asset management, sits on both sides of that trade.
- The nuance
The theft figures are independently corroborated (1,367 bitcoin from 4,585 addresses, traced to a March 2021 build that routed seed generation through a software fallback generator on Coldcard Mk3 firmware 4.0.1 to 4.1.9), but the 4,962 findings are the volunteer group's own artificial-intelligence-generated, self-classified tallies that maintainers have not yet triaged, so "85 critical" is a claim about output volume rather than confirmed exploitability, and devices whose owners added independent entropy or a passphrase were not affected.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The loss channel here was not a smart contract but the randomness that generates keys, which means audited hardware and cold storage did not protect owners. Holders who conclude they cannot verify firmware move balances to custodians and exchange-traded products. That concentrates coin with a small number of regulated operators and shifts revenue to custody providers such as Coinbase, BitGo and AnchorWatch. The Red Team result also sets a new operating expectation. If artificial-intelligence-assisted review produces critical findings at this rate across widely used Bitcoin libraries, then disclosure volume, and the emergency patching that follows, becomes a permanent cost for wallet vendors.
What to watch
- Whether other wallet and node projects issue urgent fixes from the Red Team's disclosures, which would show the 85 critical findings are exploitable in production rather than theoretical.
- Movement of the untouched 1,159 bitcoin, since any transfer toward mixers or exchanges would test how well the circulated address list actually blocks laundering.
- Custody inflows and bitcoin exchange-traded fund creations over the coming weeks, the clearest measure of whether self-custody holders are switching to third parties.
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · crypto.news · CoinDesk · Bitcoin Magazine (opinion)
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
More from this edition
- Senate Leaves Crypto Market-Structure Bill Off the Floor With Days Left Before Recess
- Putin Signs Russia's First Comprehensive Crypto Law and Keeps the Domestic Payment Ban
- Aztec's Alpha V5 Puts Client-Side Proving in Users' Hands, and a Hidden-Information Game Is the First Test
- Oracle Key Compromise and an Account-Delegation Bug Lead the Week's Exploit Files
- Ethereum Foundation Funds Browser Tool That Checks Whether a Website Serves the Code It Published
- Circle Locks In Its Coinbase Distribution Deal for Three More Years and Rules Out a Dividend
- Miden Ships an Institutional Backend That Enforces Compliance Without Holding Keys
- A 100 Million Token Unlock, a Solana Burn Vote and a Lido Buyback Test Who Actually Sets Token Supply
- Capital Concentrates as Robinhood's Chain Grows on Memecoin Trading and Solana Funds Take in Nothing
- Binance Sues Payment Firm RedotPay for $470 Million as BitMart Gives United States Users Days to Withdraw
- Bitcoin Holds Above $64,000 as Traders Position for a $101 Billion SpaceX Share Unlock
Comments
0No comments yet.