Bitcoin Red Team uncovers 85 critical codebase flaws
- AI code scans found 85 critical bugs across 390 open-source Bitcoin software repositories.
- Western safety guardrails forced security researchers to use open-source Chinese LLMs for vulnerability audits.
- The Coldcard firmware drain is driving self-custody holders into Wall Street ETFs and KYC exchanges.
Machine-speed auditing has broken single-signature self-custody.
A week after on-chain signatures linked CoinKite leadership to flawed firmware code, the fallout metastasized from a single hardware bug into an ecosystem-wide threat. In firmware introduced in March 2021, Coldcard devices defaulted to a weak random number generator with only 2^32 entropy. Automated drainer bots exploited the predictable keys, sweeping 1,816 Bitcoin worth $114 million from passive stackers whose average coin dormancy exceeded four years.
The attack marked a turning point in automated exploits. On TFTC, Galaxy Research head Alex Thorn detailed how wave-one attackers programmatically swept addresses within 10 seconds of receiving deposits, using rigid 30 sat/vbyte fees. Yet while black-hat hackers deployed unrestricted LLMs to scan public codebases, defensive researchers ran into domestic red tape.
When security teams analyzed local blockchain data, American AI platforms triggered safety downgrades. To bypass Western guardrails, researchers were forced to run open-source Chinese language models to audit hardware wallet software. Adversaries face no such friction when deploying automated scripts.
To fight back, an industry alliance called the Bitcoin Red Team launched a massive automated audit. Led by developer Cali and Anchor Watch CEO Rob Hamilton, the team spent over $40,000 in OpenSats-funded API tokens using models like GPT Sol and Claude Opus. The harness processed 171,000 lines of code across 390 open-source repositories, flagging 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities.
The sheer speed of discovery forced immediate operational halts. Developers behind projects like Bolts exchange temporarily paused operations to patch zero-day flaws before automated hacking scripts could exploit them. Audit leads reported finding 2.3 critical or high-severity flaws per person per hour, proving that human code reviews can no longer keep pace with machine-scale inspection.
On Bitcoin And, podcast host David Bennett warned that this security vacuum is triggering a flight to institutional custody. Wall Street analysts from Cantor Fitzgerald and FRNT Financial noted that the loss of faith in cold storage is driving sovereign holders into spot ETFs and corporate vaults like Coinbase and Unchained.
Bad firmware accomplished what years of regulatory pressure could not. By exposing the fragility of single-key setups, automated AI tools are forcing non-custodial Bitcoin back into tracked, KYC-compliant institutional hands.
Source Intelligence
- Deep dive into what was said in the episodes
Zombie Canary | Bitcoin News • Aug 6
- The Bitcoin Red Team, led by Cali and Rob Hamilton, secured funding from OpenSats to audit 390 open-source repositories following the Cold Card exploit. The team used AI models to identify 4,962 security findings across the ecosystem.
- The Red Team security review identified 85 critical and 635 high-severity vulnerabilities across open-source Bitcoin codebases. Hamilton revealed that a custom 171,600-line testing harness will eventually be open-sourced to allow companies to audit closed-source projects.
- Wall Street analysts at Cantor Fitzgerald and FRNT Financial argue the Cold Card exploit will push self-custody users toward managed custodians and spot ETFs. The shift undermines the non-KYC status of many long-term Bitcoin holders.
- A honeypot address generated using flawed Cold Card firmware 4.0.1 was swept by an automated hacker bot within ten seconds of deposit. This immediate exploit confirms hackers are continuously scanning pre-compiled lists of vulnerable addresses using automated tools.
- David Bennett warns that Bolts' expired warrant canary has become a zombie canary, destroying the trust required for self-custody services. Bennett argues that failing to re-up a canary on schedule indicates organizational duress or operational negligence.
Also from this episode: (5)
Safety (1)
- David Bennett explains that the Red Team does not publish detailed vulnerability reports to prevent a race against active exploiters. Responsible disclosure requires the team to report bugs privately to developers before public updates are issued.
Regulation (2)
- European financial watchdogs warn that scammers are exploiting the MiCA deadline by impersonating regulators to target users of unauthorized exchanges. Under the new rules, only 320 entities secured licenses, leaving 1,700 forced to cease operations.
- Senator Thom Tillis reports that the White House is reviewing draft text of the Crypto Clarity Act. However, legislators face a narrow timeline to secure a consensus vote before the Senate adjourns for recess.
Russia (1)
- Russian President Vladimir Putin signed a comprehensive cryptocurrency framework into law, restricting retail investors to an annual purchase limit of $3,700 per intermediary. The law bans internal crypto payments while licensing exchanges and custodians.
Stablecoins (1)
- Japanese stablecoin issuer JPYC completed an extension of its Series B funding round, raising its total to $38 million. David Bennett disputes the stablecoin label for JPYC, arguing the yen's high volatility disqualifies it from representing true stability.
Not Cold Enough | Bitcoin News • Aug 3
- David Bennett states Coldcard models Mark III, Mark IV, Mark V, and Q with firmware 4.x+ were compromised by a predictable seed generation vulnerability, while firmware 3.x models appear unaffected. The flaw, active since 2021, stemmed from a software error that reduced entropy from 2^256 to approximately 2^32 bits, making wallet seeds easily guessable.
- Bitcoin began moving from affected Coldcard addresses around July 30th, 2026, via coordinated, automated sweeps targeting large balances first (over 1.15 BTC), then smaller amounts in subsequent waves. Attackers could generate candidate seeds and compare them to the public blockchain without direct access to devices.
- CoinKite initially dismissed public warnings, continued to sell affected products for 48 hours after the vulnerability was known, and later released a firmware update that reportedly bricked devices. David Bennett argues CoinKite's failure is inexcusable and recommends never using their products again, including OpenDimes and BlockClocks.
- Volunteer teams, including BTC Sessions and Rob Hamilton, provided extensive support to affected users, with BTC Sessions reporting efforts protected "tens of millions of dollars." Foundation Devices also assisted Coldcard users, highlighting a community-driven "immune system" approach to crisis.
- David Bennett advises immediately migrating funds from any CoinKite product; he suggests using centralized exchanges like Coinbase or Kraken as a temporary measure if other self-custody options are untrustworthy or unavailable. He emphasizes avoiding panic and performing test transactions.
- David Bennett describes this incident as a "crossing the Rubicon" moment, where AI's ability to automate exploit discovery against vast code repositories means continuous, daily security audits are now essential. He suggests this creates a "security moat," raising costs for smaller projects.
- David Bennett proposes "swarm audits" where community members pool resources (AI tokens, compute, human review) to continuously vet open-source codebases. He successfully used Grok to audit Bitbox 02 Nova's code, underscoring the potential for collective vigilance.
- A "second layer" of sophisticated phishing attacks emerged, using truthful information about the Coldcard vulnerability, legitimate links, and urgent calls to action to trick users into revealing seed phrases or installing malicious software. David Bennett warns no legitimate manufacturer will ever ask for a seed phrase.
- David Bennett places sole blame on CoinKite founder Rulo Novak for the "shitty code" and systemic failure, rejecting attempts to extend liability to influencers like Matt Odell or Marty Bent, who are investors in CoinKite through their firm 1031.

Marty Bent
#780: Dissecting The Coinkite Hack with Alex Thorn • Aug 5
- Alex Thorn and Galaxy Research are tracking a multi-wave exploit targeting private keys generated on Coinkite Coldcard hardware wallets. Over 94 victims have contacted Galaxy Research to share drained addresses.
- The vulnerability stems from a weak random number generator introduced in Coldcard firmware version 4.0.0 on March 17, 2021. Marty Bent urges users with affected firmware to migrate funds immediately.
- Block Inc. engineers identified Wave 1 of the attack, which occurred over a 41-minute window on July 30th UTC. The automated attack consolidated funds into four collector addresses using a fixed fee of 30 satoshis per vByte.
- Alex Thorn reports that the stolen coins had a median dormancy of roughly four years, indicating the victims were long-term savers. No stolen UTXOs were created before the March 2021 firmware release.
- Wave 3 of the attack proved significantly more sophisticated than previous waves, utilizing 293 independent transactions. These funded 293 staging addresses and ultimately deposited funds into 293 P2WSH vaults.
- Alex Thorn reports that zero multisig setups have been breached in Waves 1, 2, or 3. While threshold multisigs using multiple vulnerable Coldcards remain technically exposed, attackers have not yet targeted them.
- One victim lost 17 Bitcoin, with 7 to 10 coins routed through Thorchain to an offshore casino called dual.com. The casino refused to freeze the funds without a police report, highlighting the need for legal hold authority rules.
- Alex Thorn criticizes US artificial intelligence safeguards for blocking defensive cybersecurity operations. Security teams like Hugging Face have been forced to use Chinese open-source models like Qwen to bypass US frontier model safety filters.
- Alex Thorn predicts this vulnerability will damage the viability of single-signature hardware wallets, arguing that collaborative multisig setups represent the necessary future of self-custody.
- According to Marty Bent, collaborative custody provider Unchained Capital secures over $12 billion in Bitcoin for more than 12,000 clients.
Also from this episode: (1)
Models (1)
- Alex Thorn highlights growing government interference in AI development, citing a midnight phone call from the United States government to Anthropic. This call halted the release of Anthropic's Mythos model.