A collective of 16 developers, operating under the group name Bitcoin Red Team, has identified 4,962 security vulnerabilities spanning 390 different cryptocurrency projects. The findings include 85 critical and 635 high-severity issues, as reported by Calle, the pseudonymous creator of the Cashu ecash protocol and current coordinator of the initiative.
Surge in AI-assisted crypto security
Bitcoin Red Team’s audit leveraged advanced artificial intelligence models to probe Bitcoin wallets, cryptographic libraries, and critical infrastructure linked to digital asset networks. Their campaign clocked roughly 27 hours of activity, during which the group averaged 2.31 high or critical findings per person per hour. Calle noted this detection rate has increased over time, citing continuous improvements to the team’s automated analysis tools.
As digital assets and decentralized finance systems become more sophisticated, security researchers and developers have increasingly turned to AI for vulnerability detection. The current sweep by Bitcoin Red Team highlights the growing role of automation and machine learning for proactive security in the sector.
Mini dictionary: Bitcoin Red Team, an independent group of security researchers focusing on identifying and disclosing vulnerabilities in Bitcoin-related software and tools by leveraging artificial intelligence for auditing and testing.
Recent Coldcard exploit prompts urgent review
The Red Team’s coordinated audit follows a significant security incident linked to the Coldcard hardware wallet. Beginning on July 30, unauthorized Coldcard sweeps have stolen more than $100 million from user wallets, underscoring the risk of vulnerabilities in widely trusted crypto hardware solutions.
This incident has highlighted the urgency for thorough security assessments, prompting developers and independent groups to intensify their scrutiny of software and hardware wallets using both manual and automated approaches.
| Project | Number of Findings | Critical Issues | High Severity Issues |
|---|---|---|---|
| All projects (390) | 4,962 | 85 | 635 |
AI transforms security audits
The integration of AI tools into security research has already demonstrated its potential to uncover critical software flaws. In June, an AI-aided audit of the privacy-focused cryptocurrency Zcash identified a bug that could have enabled the creation of unlimited counterfeit ZEC, illustrating both the scale of hidden risks and the effectiveness of machine-driven solutions.
With vulnerabilities increasingly identified by automated systems, industry experts have observed a shift in how audits are conducted, prioritizing continuous, scalable scanning over periodic reviews.
In under 27 hours, the Bitcoin Red Team recorded 4,962 security findings across 390 cryptocurrency projects, including 85 that were categorized as critical issues.
The ongoing campaign suggests developers may need to expand their focus on AI-powered testing and rapid response, particularly as malicious actors also begin using similar technology.





USDT
AAPL
