A unpaid information radical called the Bitcoin Red Team uncovered 4,962 vulnerabilities, 85 of them critical, crossed 390 open-source Bitcoin projects implicit a 27-hour agelong aft the Coldcard hack.
Key Takeaways
- The Bitcoin Red Team filed 4,962 findings crossed 390 repositories successful 27.5 hours.
- Opensats funded the audit with astir $40,000 arsenic 16 researchers combined AI tools with manual review.
- Privacy and coinjoin tools carried the highest stock of superior flaws, astatine 24% of captious findings.
A Response to the Coldcard Exploit
The Coldcard hardware wallet exploit drained bitcoin (BTC) from semipermanent holders aft a firmware bug dating to March 2021. Losses person climbed past $116 million crossed much than 1,800 BTC pulled from implicit 5,200 addresses.
That occurrence prompted a unpaid effort called the Bitcoin Red Team, led by BTC dev Calle alongside Rob Hamilton, CEO of self-custody insurer Anchorwatch. They launched an exigency audit of the broader bitcoin open-source ecosystem to trial whether different wide utilized wallets and codification libraries stock akin weaknesses to the 1 that sank Coldcard users.
Image source: XSixteen information researchers spent 27.5 hours combing done 390 open-source bitcoin repositories, combining artificial quality (AI)-assisted investigation with manual review. The squad filed 4,962 full information findings, including 85 classified arsenic captious and 635 rated high-severity (a gait averaging 2.31 high- oregon critical-severity findings per researcher, per hour).
Funding for the sprint came from Opensats, a nonprofit that backs open-source bitcoin development, which contributed adjacent to $40,000 to enactment the researchers’ work. Calle described the authorities of ecosystem information arsenic “extremely bad.”
Analysts who tracked the audit successful existent clip noted that lone astir one successful 5 findings had been independently reproduced truthful far, showing that galore of the flagged issues inactive request confirmation earlier developers could beryllium definite of their real-world severity.
Where the Flaws Are Concentrated
Privacy and coinjoin tools (software designed to obscure the way of bitcoin transactions onchain) accounted for the highest attraction of superior issues, representing 24% of captious findings contempt making up a smaller stock of the full projects reviewed. Cryptographic libraries, by contrast, generated the largest earthy fig of findings astatine 1,101, but a comparatively debased 10% of those were rated high-severity, suggesting that codification is mostly much mature adjacent though it draws the astir scrutiny from researchers.
Most of the 390 projects reviewed had fewer oregon nary captious issues; the existent information seemed to beryllium concentrated successful a smaller acceptable of tools handling backstage cardinal generation, signing, and privacy-preserving transactions, the aforesaid class of bundle astatine the basal of the archetypal Coldcard nonaccomplishment that started this full effort.
The timing of the unearthing matters, fixed bitcoin’s self-custody civilization has spent the past 2 weeks absorbing the standard of the Coldcard losses, with Canadian users unsocial accounting for astir a 4th of the funds stolen.
The Future Needs Assessing
The Bitcoin Red Team has noted that the audit is the archetypal signifier of an ongoing effort alternatively than a one-time event, with plans to enactment done the backlog of findings, corroborate which vulnerabilities are genuinely exploitable, and coordinate liable disclosure with the affected projects earlier immoderate details are made public.
For a self-custody civilization inactive absorbing the size of the Coldcard losses, the audit doubles arsenic grounds that white-hat researchers are present moving astatine a gait person to that of attackers.

1 hour ago








English (US)