A group of 16 volunteers just did in 30 hours what would normally take professional audit firms months. The Bitcoin Red Team, a grassroots security initiative, scanned roughly 390 open-source Bitcoin-related projects and surfaced 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities.

The effort wasn’t academic. It was triggered by a very real, very expensive disaster.

The Coldcard exploit that started it all

The Bitcoin Red Team’s audit sprint was a direct response to a firmware vulnerability in Coldcard hardware wallets. That flaw, buried in the device’s random-number generator, led to estimated losses between $70 million and $114 million in stolen Bitcoin.

In English: the thing responsible for generating your private keys was broken, which meant attackers could predict those keys.