Crypto Prices

Bitcoin Red Team Uncovers Nearly 5,000 Vulnerabilities in Bitcoin Projects Amid Coldcard Wallet Crisis

37 minutes ago
2 mins read
1 views

Bitcoin Red Team Initiative

In a significant push for enhanced security, a volunteer initiative dubbed the Bitcoin Red Team has uncovered 4,962 potential vulnerabilities across 390 Bitcoin-associated projects in less than 30 hours of AI-aided code assessments. Out of these, 720 issues have been categorized as either high or critical severity, raising alarms about the overall security landscape of Bitcoin software.

Motivation and Findings

This comprehensive security review was initiated following recent attacks on the Coldcard hardware wallets, prompting the team to take a closer look at various components of the Bitcoin ecosystem, which includes libraries, wallets, and infrastructure software. Prominent Bitcoin developer Calle shared insights on social media platform X, revealing a critically alarming situation within the ecosystem, with the initiative averaging about one high-risk exploit identified per individual reviewer each hour.

Team Composition and Support

The Bitcoin Red Team is an assemblage of volunteers, including AnchorWatch’s CEO Rob Hamilton, who are leveraging both AI-driven tools and manual inspections to locate software vulnerabilities. Calle noted that within just the first 12 hours of the campaign, the team managed to disclose significant vulnerabilities to several projects.

This initiative is backed financially by OpenSats, incurring costs of about $10,000 each day to maintain the technological effort. Moreover, the reviews have been supported by Kimi Moonshot, which has provided access to advanced AI tools to assist the volunteers in their mission to scrutinize Bitcoin software. The team is actively seeking contributions from the Bitcoin community in the form of computing accounts or digital currency to sustain their work.

Security Breaches and Impact

The urgency for this review campaign was catalyzed by a serious wallet security breach that compromised the assets of Bitcoin users. Research from Galaxy Research has confirmed that attackers managed to pilfer 1,596 BTC from roughly 7,300 Bitcoin addresses during three key assaults, with additional smaller incidents linked to vulnerabilities in the Coldcard seed generation process. There is also an indication of a potential fourth wave of theft, which may elevate total losses to approximately 2,055 BTC, pending further victim verification.

Recent on-chain analyses have shown that around 90% of the stolen Bitcoin is still held by the attackers, with some recent activity noted as assailants begin moving portions of the stolen assets through Bitcoin mixers, although many of the largest amounts remain untouched.

Coldcard Vulnerabilities

The Coldcard hardware wallet issues stemmed from flawed firmware changes made in March 2021, which skewed how wallet seeds were generated, ultimately relying on less secure pseudo-random generators. While the vulnerabilities have since been addressed through emergency firmware updates, users are cautioned that simply updating does not secure previously created wallets; they must generate new seed phrases and migrate their Bitcoin to new addresses accordingly.

Ongoing Efforts

As investigations into the Coldcard vulnerabilities advance, the Bitcoin Red Team continues to report new findings to the software projects impacted by the security concerns. Calle confirmed that critical vulnerabilities have been communicated confidentially to the project maintainers, who are currently working on remedial strategies. As the reviews of additional Bitcoin repositories progress, the team remains committed to validating reported vulnerabilities and enhancing the overall security of the Bitcoin network.

Popular