Bitcoin Red Team Flags 85 Critical Bug Reports
A volunteer Bitcoin security group says it has filed 4,962 findings across 390 projects after a rapid audit push, including 85 issues it classified as critical and 635 as high severity.
The figures came from developer Calle, who described the work as 27.5 hours into the effort. In an earlier post, he said the situation was "extremely bad" and estimated the team was finding roughly one critical exploit per hour per person. CoinDesk reported that 16 Bitcoin developers were involved and that many of the critical reports had been quickly verified by project owners.
The project appears to combine automated scanning with human triage. Rob Hamilton, who said he is building the red team's agent harness, wrote that the main bottleneck is not finding issues but routing reports to the right maintainers. He said the setup had already supported more than a dozen disclosures across 150 scanned repositories.
The most important unresolved question is severity after maintainer review. The public count reflects the team's submitted classifications, not a completed ecosystem-wide advisory process. Still, the scale matters for Bitcoin infrastructure because many wallets, libraries, and adjacent projects share code paths, dependencies, and assumptions. If even a small share of the reported critical findings holds up, maintainers may face a concentrated disclosure and patching cycle.