Bitcoin ecosystem reveals hundreds of critical security bugs
Security researchers have uncovered a wave of vulnerabilities across the Bitcoin ecosystem. An audit identified 85 critical flaws in Bitcoin applications, alongside 635 high‑risk issues, bringing the total reported findings to nearly 5,000. Only 147 of these reports have reached the developers responsible for remediation. The investigation was sparked by a Coldcard hardware‑wallet seed‑generation error that limited entropy to 32 bits, exposing devices to attack.
Separate analysis highlighted a long‑standing weakness in the CryptoJS JavaScript library, where its random() function relied on Math.random, leading to a $5.7 million loss affecting 2,114 addresses. The Bitcoin Red Team later disclosed more than 1,000 high and critical bugs in wallets, node software, and related tools. Mobile wallets are especially vulnerable because of their large user base and inconsistent update practices. Mining pools, infrastructure tools, exchanges and privacy tools together account for roughly a quarter of all findings.
The disclosures underscore the complexity of Bitcoin’s expanding software stack and the importance of continuous security testing and responsible disclosure to protect user funds.
Entities: AnchorWatch · Baseboard Management Controller (BMC) · Bitcoin · Bitcoin network · Coldcard · Coldcard hardware wallet · CryptoJS · HPE iLO · OpenBMC · Rob Hamilton
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] A Coldcard seed‑generation flaw reduced entropy to 32 bits, exposing devices to attack. (Coldcard incident)
- [○ 1 SOURCE] Around 5,000 security findings were reported, including 635 high‑risk issues. (German security audit)
- [○ 1 SOURCE] Mining pools, infrastructure tools, exchanges and privacy tools each accounted for roughly 20‑24% of the findings. (German security audit)
- [○ 1 SOURCE] Only 147 of the reported findings have been sent to developers for fixing. (German security audit)
- [● 2 SOURCES] Mobile Bitcoin wallets have the highest exposure due to large user bases and delayed updates. (Security analyses)
- [○ 1 SOURCE] The Bitcoin Red Team uncovered more than 1,000 high and critical vulnerabilities across wallets and software. (Bitcoin Red Team report)
- [● 2 SOURCES] 85 critical vulnerabilities were discovered in Bitcoin applications. (multiple security audits)
- [○ 1 SOURCE] A weakness in CryptoJS's random() function caused $5.7 million in theft affecting 2,114 addresses. (CryptoJS vulnerability analysis)