In brief
- Cashu creator calle said the campaign logged 85 critical and 635 high-severity issues in its first 30 hours.
- Contributors each prompt their own agents, which the group says produces a wider spread of hits than a single method would.
- Privacy and coinjoin projects carried the highest share of serious findings, at 24%.
A volunteer group calling itself the Bitcoin Red Team has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, running what it describes as a “large-scale ecosystem audit” with AI agents doing much of the scanning.
Pseudonymous developer calle, who created the Bitcoin ecash protocol Cashu, published the campaign's first situation report on Wednesday. It puts 85 findings at critical severity and 635 at high, together 14.5% of the corpus and an average of 1.85 serious issues per project, filed at 166 findings an hour. He said the team has grown to 16 people working around the clock; the report logs 17 contributors, 14 of them human and three automated.
Much of the work is still manual, "hand holding the AI," calle wrote, though automated harnesses are improving, and 91% of findings arrived through automated scan intake. Letting everyone use their own preferred review method "has proven to be the most effective strategy," he said, because contributors prompt their agents differently and turn up different bugs. Around 21% of findings have been dynamically reproduced with proof-of-concept code.
The severity spread varies sharply by category. Privacy and coinjoin tools returned the highest proportion of high-or-critical findings at 24%, followed by swaps and exchanges at 21% and payments and merchant tools at 17%. Cryptographic libraries and SDKs produced the largest raw volume at 1,101 findings, but only 10% cleared the high bar.
Maintainers are getting flooded
Only 19 projects, under 5% of those reviewed, have had findings disclosed upstream so far, and calle acknowledged the campaign is adding to a difficult moment for maintainers.




