The Bitcoin Red Team—a team of 16 globally distributed members working around the clock—has conducted a large-scale security audit of the Bitcoin ecosystem’s codebases. Over 27.5 hours, 390 projects were reviewed, resulting in 4,962 findings, including 85 critical and 635 high-risk vulnerabilities.
Most of the work is still performed manually—people direct AI agents, with each individual using their own approach, leading to diverse results. Automated tools are continuously improving in parallel. Most of the critical reports have already been quickly confirmed by project owners—critical findings are reproduced via proof-of-concept in a local regtest environment before being submitted.
The team acknowledges that the influx of reports creates stress for maintainers, but emphasizes the importance of publishing findings as quickly as possible—validation using AI is now nearly free, and those not part of the red team will still discover the same vulnerabilities anyway.
