LIVE MARKET DATA MON 10 AUG 2026 UTC [ VIEW ALL COINS ]
// Bitcoin

Bitcoin Red Team Scan Flags 85 Critical Bugs, $100M+ Losses Across 390 Repos

Post-Coldcard audit by Bitcoin Red Team logs 4,962 findings across 390 repositories, with 85 rated critical and losses topping $100M.

Aisha Rahman · ·2 min read
Bitcoin Red Team Scan Flags 85 Critical Bugs, $100M+ Losses Across 390 Repos

Bitcoin Red Team, a security research initiative focused on the Bitcoin software supply chain, has logged 4,962 findings across 390 repositories in a sweep triggered by the recent Coldcard exploit, according to coinotag.com. Of those findings, 85 were classified as critical, and the group’s tally puts losses tied to the underlying vulnerabilities at more than $100 million.

The scale of the audit — nearly 5,000 individual findings across almost 400 codebases — points to a broader attack surface across Bitcoin-adjacent tooling than a single hardware wallet incident would suggest. For a market that leans heavily on self-custody as a differentiator versus centralized exchanges, a critical-bug count in the dozens is the kind of figure on-chain researchers will want reconciled against actual exploited funds versus theoretical exposure.

From Coldcard to a wider repo sweep

The review follows an exploit involving Coldcard, a hardware wallet brand popular among Bitcoin holders who prioritize air-gapped signing over convenience. ElrondScan previously reported that mempool congestion spiked to 89,031 transactions — the highest level since February — coinciding with the Coldcard scare, as users rushed to move funds in response to the disclosed risk.

That mempool spike now reads as an early market signal of the underlying issue Bitcoin Red Team’s broader scan has since quantified. Moving from a single-product incident to a 390-repository audit suggests the team treated the Coldcard case as a trigger to stress-test adjacent code rather than an isolated event.

What 85 critical findings and $100M mean for traders

For active traders and custodial-risk desks, the headline number that matters is the loss figure: over $100 million tied to the flagged vulnerabilities. That places the audit’s findings in the same tier as mid-sized DeFi exploits, but with the added complication that the affected surface is wallet and infrastructure code rather than a single smart contract.

The 85 critical-severity findings, out of nearly 5,000 total, imply a roughly 1.7% critical-rate across the scanned repositories — a ratio that will likely be used by security teams to benchmark future audits of Bitcoin-ecosystem software. Until individual repository maintainers confirm patches or disclose remediation timelines, the practical takeaway for holders is to treat firmware and signing-device updates as time-sensitive rather than optional.

No breakdown of which specific repositories, wallets or protocols account for the $100 million in identified losses has been published alongside the aggregate figures. On-chain researchers will be watching for Bitcoin Red Team to release a fuller disclosure list, which would allow exchanges, custodians and wallet vendors to cross-check exposure against their own dependency trees.

Read more: Bitcoin Mempool Swells to 89,031 Txs, Highest Since February Amid Coldcard Scare

Sources

More Bitcoin