Join Nostr
2026-08-05 20:58:18 CEST

flash on Nostr: ⚡️🚨 NEW - calle : « Bitcoin Red Team update: we've grown to 16 globally ...

⚡️🚨 NEW - : « Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7

We're running a large-scale ecosystem security audit across bitcoin code bases.

27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues.

We're at 2.31 h+c findings per person per hour

We're ramping up.

Much of our work is still manual (hand holding the AI) but our automated harnesses are getting better at the same time.

So far, letting everyone use their own favorite review method has proven to be the most effective strategy.

We're getting a lot of diverse hits because everyone prompts their agents a little differently.

The big spike you're seeing is us backfilling Rob's insane review dump before we started the present campaign.

Thank you to our supporters , Finn Puklowski, Steve, and OpenCode , wafer_ai and Kimi_Moonshot for sponsoring, for paying the bills, and for providing the inference.

We've been reaching out to many folks. Most of the critical reports we've made so far were quickly verified by project owners. We know we're hitting real targets.

There's a lot of chaos right now in the ecosystem. We absolutely understand that many people are being bombarded with security issues right now.

We're trying our best to give you actionable findings. Most of the critical results are reproduced with a proof of concept in local regtest environments before we report. Please use AI to verify and reproduce our findings.

We're sincerely sorry if our reports added stress to your already stressful day.

However, we believe it's important to send out these findings as quickly as possible because 1) the project owners are the best to validate them (validation is almost free with AI now) and 2) others who aren't on the red team will arrive at the same findings as we did.

We're getting better at sorting out the slop, verifying our findings, and at getting in touch with the relevant people. Please bare with us. »