After the incident of Coldcard happened, a group of people which consist of user @Rob1Ham on X
(CEO of AnchorWatch),
@callebtc , @PortlandHODL, @danielabrozzoni, @lylepratt, @stutxo, @benthecarman, @thesimplekid, etc.
Created a team called
Bitcoin Red Team, aka Red Team, whose aim was to work endlessly launching a huge wave of reviews on many core Bitcoin projects, especially the crypto libs, wallets, infra, and more.
Checking for critical exploits and vulnerabilities through the use of human effort and AI
(like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2).
In 27.5 hours, with almost
10k spent in 24hours, and they have reported
1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilitiesWhich the ckpool was among the security findings the Red Team detected, and according to
@-ck statement, all the possible security holes were swiftly addressed.
At the time of posting this, the Red Team has no website or GitHub repository link.
Having people like this who care about Bitcoin is truly helpful and makes us, as Bitcoin investors, feel safer. So, I think their efforts deserve appreciation. Checking whether a wallet or any project supports Bitcoin will clearly improve control, and any problems can be detected immediately. Furthermore, I didn't expect the numerous vulnerabilities they discovered in the systems of these projects or wallets.
If these issues aren't addressed thoroughly, incidents like the Coldcard incident could recur in the long term. Fortunately, there are still people like them who care about the Bitcoin and crypto community. Hopefully, this will help Bitcoin and all its projects remain secure and improve. If an incident like Coldcard were to happen again,, it would be traumatizing for many. Hopefully, things will improve now.