Coordinated Bitcoin Security Campaign Uncovers Nearly 5,000 Software Issues

Coordinated Bitcoin Security Campaign Uncovers Nearly 5,000 Software Issues

A rapid security assessment of open-source Bitcoin software has revealed a significant number of vulnerabilities.

Approximately 4,962 findings were identified across 390 projects during a 30-hour campaign concluded on July 31, 2024. The initiative, spearheaded by 16 researchers and aided by OpenSats and OpenCode, uncovered issues within crypto libraries and software development kits, which accounted for the majority of reported problems – specifically 1,385 findings.

The research team utilised AI systems overseen by human reviewers to systematically examine the code. A key finding indicated a ratio of roughly two critical or high-severity issues per person-hour spent on the review process. Eight-five critical issues and 635 high-severity findings were identified, with a total of 720 recorded in the most serious categories.

Matt Corallo, a Bitcoin Core developer, dedicated time to reviewing one project as part of the initiative. One reviewed project reportedly completed the assessment without any reported defects. The campaign’s average output was approximately 166 findings per hour.

On July 31, 2024, daily active Bitcoin addresses totalled roughly 0.98 million. This figure is consistent with activity levels observed in December 2024 when daily active addresses were similarly around 0.98 million. The scale of the findings highlights ongoing efforts to bolster security within the open-source Bitcoin ecosystem.


Written by James Tobias
Bitcoin Desk

Share