The $130 million Coldcard hack did more than empty wallets. It started the largest community-funded security audit in Bitcoin history — and the results should terrify anyone who touches this ecosystem.
4,962 findings. 85 critical. 635 high severity. In 27.5 hours. Across 390 open-source projects.
That is the scoreboard from the "Bitcoin Red Team" — a ragtag crew led by Calle (creator of the Android version of Bitchat) and Rob Hamilton (CEO of Anchorwatch, a Bitcoin self-custody insurance company). Funded by OpenSats, they have burned through $40,000+ in AI tokens tearing through Bitcoin’s open-source software stack, hunting for the next Coldcard before the black hats do.
"27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour," Calle posted in the team’s latest update.
The audit runs on some of the most expensive frontier models in existence — Kimi K3, GPT Sol, Fable, Opus, GLM5.2. A custom harness that once stood at 171,599 lines of code identifies, reproduces and packages vulnerabilities into responsible disclosures. The team says it will open-source the harness so Bitcoin companies can run it against their own closed-source code.
The impact is already real. Boltz exchange paused operations just to catch up with AI-driven hacking attempts. Engineers across the industry dread the cold DM from Hamilton or Calle — you know what a message from the Red Team means.
Rob Hamilton, whose company literally insures self-custody, called the Coldcard RNG exploit a "spiritual attack" on Bitcoin:
"There is no Bitcoin without self-custody. This is non-negotiable."
Now here is the part that should make you furious.
The white hat who integrated OpenAI’s cyber program into the Red Team effort — after KYC’ing and completing months of onboarding — woke up yesterday to find himself blocked. The model refused further analysis of a codebase he had already responsibly disclosed, with confirmed legitimate findings. Error code: "cyber_policy."
So let’s get this straight. The black hats who stole $130 million in Bitcoin are not blocked. They are not asking permission. They are running the same frontier models — probably better ones — against every wallet codebase on Earth, right now, unrestricted.
The white hats — the people actually trying to protect your coins — get throttled by a "safety-first" AI lab the moment they become useful.
Black hats: unrestricted. White hats: censored. And the people telling you to "trust the process" wonder why Bitcoiners are going back to Chinese open-source models.
The good news: the Red Team keeps working. 85 critical flaws found so far — and counting. The bad news: every single one of those flaws was a wallet or a library that could have been drained while nobody was looking.
The only thing standing between your sats and the black hats is a community-funded audit burning $40K in AI tokens — and an AI company that keeps getting in its way.
So while the black hats run unrestricted and the white hats get blocked by "cyber_policy" — who exactly is protecting your coins? And what happens when the next $130 million theft is yours?
Buy your Bitcoin through Bull Bitcoin with coupon code LOVEISBITCOIN and take custody of your own keys: https://loveisbitcoin.com/bull
Source: Bitcoin Magazine | Related: OpenAI blocked the white hat mid-audit