A rapid review has revealed a significant number of potential weaknesses across the Bitcoin open-source software landscape.
The Bitcoin Red Team, a volunteer group utilising artificial intelligence, identified nearly 5,000 vulnerabilities within 390 projects. This follows recent security incidents, most notably the $100 million theft from the Coldcard hardware wallet. The operation was conducted by sixteen developers over approximately 29.8 hours.
Calle, a Bitcoin developer involved in the review, stated that there is currently considerable disruption within the wider Bitcoin ecosystem. He added they were averaging one critical exploit per hour per individual within the team. The group’s assessment included identifying 720 issues rated as high or critical in severity.
Approximately 21.4% of the identified vulnerabilities were confirmed to be reproducible. This means that technical teams can attempt to recreate the conditions leading to the potential problem. The extensive review reflects the complexity and scale of the Bitcoin ecosystem, comprised of numerous open-source projects.
Rob Hamilton, CEO of AnchorWatch and a member of the Bitcoin Red Team, oversaw the effort. AnchorWatch provides security services and supports the Bitcoin Red Team’s volunteer activity. This assessment follows a recent hack targeting the Coldcard hardware wallet.
The review highlighted the ongoing need for vigilance within the Bitcoin community despite efforts to enhance security. The finding represents a significant quantity of potential weaknesses requiring investigation by developers. Further analysis is now underway to determine the impact and appropriate remediation strategies.
Written by Daniel Brooks
Security Desk