News linked to both this project and an event.
According to Cointelegraph, AnchorWatch CEO and Bitcoin Red Team founder Rob Hamilton stated that after integrating OpenAI Trust & Cyber capabilities into the Bitcoin Red Team's security research work, he faced access restrictions the next day and was forced to switch back to using Chinese open-source AI models to continue research. The Bitcoin Red Team has currently discovered 1,288 critical and high-risk vulnerabilities in the Bitcoin ecosystem, and research work significantly accelerated after the Coldcard hardware wallet was hacked (over $100 million in Bitcoin stolen). Hamilton commented on this: "Black-hat hackers face no restrictions, while white-hat researchers dedicated to reducing risk are excluded."
Odaily News: The Bitcoin Red Team volunteer security initiative has scanned approximately 150 Bitcoin-related code repositories and disclosed more than a dozen vulnerabilities. The team is developing an open-source AI platform to audit Bitcoin software, covering wallets, cryptographic libraries, infrastructure, and other projects. AnchorWatch CEO Rob Hamilton stated that the team has so far spent approximately $20,000 on various AI services, using Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus, as well as Z.ai's GLM 5.2 to identify vulnerabilities and generate related documentation. Pseudonymous Bitcoin developer Calle said that over the past 12 hours, the team has reported critical vulnerabilities to multiple projects, discovering on average roughly one critical vulnerability per person per hour, with daily spending of around $10,000. The team has not disclosed the affected projects or details of the vulnerabilities.
据 Bitcoin Magazine 报道,在 Coldcard 硬件钱包漏洞事件引发行业关注后,由 Calle与 Anchorwatch 首席执行官 Rob Hamilton 推动的“比特币红队”已对 390 个比特币开源代码库展开 AI 驱动安全审计,累计提交 4,962 项问题,其中包括 85 项严重漏洞和 635 项高危问题。该项目已获得 OpenSats 支持,审计成本超过 4 万美元,并计划未来开源相关测试工具,以协助更多比特币企业和开发团队排查安全风险。
Odaily Odaily News: Bitcoin Red Team, a bitcoin security organization composed of 16 volunteers, stated that it identified nearly 5,000 potential issues during a rapid AI-assisted review of bitcoin ecosystem projects. The organization's members include AnchorWatch CEO Rob Hamilton and bitcoin developer Calle, among others. Calle stated that Bitcoin Red Team used AI tools combined with manual review to scan for vulnerabilities in open-source code repositories related to bitcoin, discovering an average of approximately 1 critical vulnerability per person per hour. Calle disclosed that within 29.8 hours of launch, the team had identified 4,962 potential issues across 390 projects, of which as many as 720 were classified as high-risk or critical. Currently, 21.4% of the findings have been reproduced. The security review initiative was launched just days after the Coldcard hardware wallet vulnerability incident, in which stolen bitcoin exceeded $100 million in value.
Odaily News: Canadian Bitcoin hardware manufacturer Coinkite has warned users of Coldcard Mk3 signing devices to migrate funds from wallets whose seed phrases were generated by affected firmware. Coinkite stated that seed phrases generated by Mk3 firmware version 4.0.1 and later, released in March 2021, may put funds at risk, with the impact extending to version 5.0.3, the final version supporting the Mk3. Coinkite said that Mk4, Q, and Mk5 models are not affected; affected users should generate new seed phrases on unaffected devices, verify backups and receiving addresses, send a small test transaction first, and then migrate the remaining funds. The company said its investigation is still ongoing and that a formal technical review will be published. Bitcoin security experts are examining a centralized transfer of unclear origin involving 594.48 BTC in single-signature addresses, valued at approximately $38.3 million. Rob Hamilton, CEO and co-founder of AnchorWatch, stated that 1,324 unspent transaction outputs were moved via 500 transactions within a three-block window, with 562 BTC subsequently consolidated into another address. Kevin Loaec, CEO of Wizardsardine, said the current hypothesis is that a low-entropy random number generator has caused insufficient randomness in some wallets' seed phrases, with the relevant flaw potentially stemming from a software library, secure element, specific device batch, or firmware version. He added that this hypothesis has not yet been confirmed, and wallets from which only partial funds were transferred may still face the risk of subsequent theft.