Bitcoin Red Team Reports Disclosures Across 150 Repositories

AnchorWatch chief executive Rob Hamilton says a volunteer group has scanned 150 bitcoin repositories and filed more than a dozen disclosures, spending about $20,000 on AI services, with the harness set to be open sourced.

Bitcoin Red Team Reports Disclosures Across 150 Repositories

AnchorWatch chief executive Rob Hamilton said on Aug. 4 that a volunteer red team (security researchers who attack systems to find flaws before criminals do) has filed more than a dozen security disclosures.

The group reports each flaw privately to the people who can fix it, and it worked through 150 bitcoin ecosystem repositories, the public folders where a project's code lives.

In an update posted on X, Hamilton, whose firm sells bitcoin insurance, put the group's spending at about $20,000 across different services. The figures are self-reported. The update does not name the projects that received disclosures.

An early working version of a red team agent harness, software that points AI models at a codebase and runs the audit automatically, needs a single API key. That key comes from OpenCode Zen, a gateway that gives one account pay-per-use access to dozens of AI models. Kimi K3, from Moonshot AI, does the scanning, and other models write the supporting documentation, all through that one key.

Version one has already found critical issues. The goal is to open source the harness for use on internal repositories, and that one key is what makes the plan practical.

OpenAI connected him with help to run its Cyber Harness. Hamilton called that scan more expensive but worth it for load-bearing parts of the ecosystem. OpenAI launched Daybreak, an AI vulnerability-detection program built on its Codex Security agent, in May 2026.

The work follows the theft that hit Coinkite's Coldcard Mk3 hardware wallet, where a seed-generation flaw let attackers sweep 594 BTC (then worth ~$38 million) from about 500 wallets in July. The red team is hunting that class of bug before an attacker finds it, and the Coldcard sweep is what a missed one costs.

Hamilton posted on July 31 that he was running emergency triage to find the source of that attack.

Calle, a pseudonymous bitcoin developer working alongside the group, wrote on Aug. 4 that the reviewers are averaging one critical exploit per hour per person. The choke points now are the requests and staging, as well as the handoff of reports.

Hamilton said his next goal is automating both ends to get humans out of the loop.

Mission Statement

Crypto gambling has a transparency problem. We're fixing it.

On-chain data and original research, not recycled press releases

Honest operator reviews and news, free from affiliate influence

Player-first reporting built on transparency and responsible gambling