# Bitcoin Red Team Files 4,962 Security Findings Across 390 Projects After Coldcard Theft

The volunteer group reported 85 critical and 635 high-severity issues in about 27 hours, while on-chain investigators tracked laundering of coins taken through the wallet flaw.

- Published: 2026-08-06T05:33:07.606Z
- Canonical: https://polylog.news/crypto/2026-08-06/bitcoin-red-team-files-4-962-security-findings-across-390-pr
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Bitcoin Magazine](https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit), [crypto.news](https://crypto.news/coldcard-attacker-holds-1159-btc-as-mixing-starts/), [CoinDesk](https://www.coindesk.com/tech/2026/08/05/coldcard-exploit-could-boost-demand-for-regulated-bitcoin-exposure-analysts-say), [Bitcoin Magazine (opinion)](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody)

Sixteen volunteer researchers working as the Bitcoin Red Team, organized by the developer known as Calle and by Rob Hamilton, chief executive of the custody firm AnchorWatch, [filed 4,962 security findings across 390 open-source Bitcoin projects](https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit) during a sprint on 4 and 5 August. The group classified 85 findings as critical and 635 as high severity. It used artificial-intelligence analysis harnesses to read wallet code, cryptographic libraries and node infrastructure faster than manual review allows, and it worked on a $40,000 grant from the funding organization OpenSats. Calle wrote publicly that the team was averaging roughly one critical exploit per researcher per hour.

The sprint followed the Coldcard incident. A firmware integration error shipped in March 2021 sent seed generation on some devices to a deterministic software pseudorandom number generator instead of the hardware random number generator on the device's STM32 chip. The private keys those devices produced were therefore reproducible. Galaxy Research has traced three rounds of thefts totalling about 1,367 bitcoin, close to $89 million at recent prices, from roughly 4,585 addresses.

Most of the stolen coin has not moved. Galaxy said the single largest theft, [1,159 bitcoin, remains untouched](https://crypto.news/coldcard-attacker-holds-1159-btc-as-mixing-starts/), while a separate attacker has begun routing smaller sums through a mixing service, starting with about 10 of 64 bitcoin sent. Investigators have circulated roughly 600 flagged addresses to exchanges, analytics firms and law enforcement.

The commercial assessment came quickly. Analysts at Cantor and FRNT told CoinDesk the breach [could push some holders toward regulated custodians and exchange-traded funds](https://www.coindesk.com/tech/2026/08/05/coldcard-exploit-could-boost-demand-for-regulated-bitcoin-exposure-analysts-say). Bitcoin Magazine's editorial argues the opposite, that [the failure was one vendor's build process, not self-custody itself](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody). Both conclusions can hold at once. The defect was an implementation error in a certified device, and the practical response for many holders is to pay someone else to hold their keys.

## What this means

The loss channel here was not a smart contract but the randomness that generates keys, which means audited hardware and cold storage did not protect owners. Holders who conclude they cannot verify firmware move balances to custodians and exchange-traded products. That concentrates coin with a small number of regulated operators and shifts revenue to custody providers such as Coinbase, BitGo and AnchorWatch. The Red Team result also sets a new operating expectation. If artificial-intelligence-assisted review produces critical findings at this rate across widely used Bitcoin libraries, then disclosure volume, and the emergency patching that follows, becomes a permanent cost for wallet vendors.

## What to watch

- Whether other wallet and node projects issue urgent fixes from the Red Team's disclosures, which would show the 85 critical findings are exploitable in production rather than theoretical.
- Movement of the untouched 1,159 bitcoin, since any transfer toward mixers or exchanges would test how well the circulated address list actually blocks laundering.
- Custody inflows and bitcoin exchange-traded fund creations over the coming weeks, the clearest measure of whether self-custody holders are switching to third parties.
