Bitcoin

Bitcoin security comes under scrutiny after nearly 5,000 flaws are found

By Kim03 | Kim Crypto News | 3 hours ago


Bitcoin security has come under scrutiny after researchers found 4,962 flaws in 390 projects within its ecosystem.

 

Bitcoin security has received a new warning after a team of volunteer developers identified 4,962 problems in projects related to the ecosystem of the largest cryptocurrency on the market. The survey analyzed 391 codebases and found only one that did not present any flaws.

 

The investigation was conducted by the so-called Bitcoin Red Team and took place over approximately 30 hours. Of the total issues recorded, 720 received a high or critical rating , while only 147 had reached the project managers for evaluation and possible correction.

The number is noteworthy, but it needs to be analyzed carefully. After all, the discovery of a vulnerability does not necessarily mean that someone has managed to exploit it or that users' funds are at risk. Still, the survey reinforces the importance of maintaining Bitcoin security as a top priority for the sector.

 

Bitcoin security reveals 720 serious flaws.

Although nearly 5,000 incidents appeared in the survey, a smaller portion received the highest severity ratings. Researchers classified 85 problems as critical and another 635 as severe.

Together, these cases represent approximately 14.5% of all findings . Most records fell into the medium, low, or informative categories. Additionally, 246 occurrences have not yet received a severity classification.

Another important point involves proving the flaws. According to data released by the team, approximately 21.4% of the identified problems presented functional proofs of concept . At the same time, about 91% of the findings originated from automated analysis tools.

Even with the extensive use of automation, researchers ruled out only eight cases as false positives. Therefore, the numbers indicate that a significant portion of the alerts deserves attention from the developers responsible for the projects.

 

Bitcoin security has an important detail in the numbers.

 

The approximately 30-hour period used to present the results may create a different impression from reality. This is because 4,101 of the 4,962 records appeared concentrated in just one hour .

This peak, however, did not correspond to a round of tests conducted at that time. The data represented previous work that was incorporated into the survey later.

Rob Hamilton, CEO of AnchorWatch, conducted an analysis before the official start of the campaign. According to him, more than US$10,000 was invested in analyzing over 100 libraries.

When this large volume is removed from the equation, the pace of the investigation changes considerably. In the other 29 hours, the researchers received approximately 840 findings, an average of nearly 29 records per hour.

 

Hardware wallets perform better.

The analysis also revealed a relevant piece of data regarding Bitcoin security . Hardware wallets and their firmware were among the categories with the lowest proportion of serious problems.

The segment presented a failure rate of 9.6% considered serious, ranking second among the categories with the best results. This data gains importance because the survey took place shortly after a problem involving Coldcard devices.

Other areas showed higher rates. Mining pools recorded 21.7% of serious failures, while infrastructure and tools reached 21.5%. Swaps and exchanges, on the other hand, accounted for 20.9%.

Privacy-focused tools accounted for the largest percentage, at 24%. However, the researchers only analyzed three projects in this category, which limits any direct comparison.

Meanwhile, cryptocurrency libraries accounted for the largest absolute volume. There were 1,385 discoveries distributed across 128 projects , representing more than a quarter of all records.

 

Coldcard's failure has increased security concerns.

The Bitcoin Red Team movement gained momentum after a problem related to seed generation on certain Coldcard devices. On July 30, Coinkite reported that some devices had started using a predictable software routine during seed generation.

The problem involved the limited participation of the safe element in generating randomness. According to the data released, only 32 bits came from this component, which reduced the search space to approximately 4.3 billion possibilities .

The incident also drew attention for its potential financial repercussions. On August 4th, Galaxy Research estimated that 1,596 BTC were stolen from approximately 7,300 addresses. A possible fourth wave of attacks could raise the losses to nearly US$130 million, although the company itself emphasized that its list of addresses was not definitive.

Furthermore, the case has once again placed the generation of random numbers at the center of discussions about Bitcoin security . Similar problems have already appeared in other projects in the sector, including the Milk Sad bug, identified in 2023, and the Ill Bloom vulnerability, associated with wallets that used a JavaScript generator considered weak.

 

Bitcoin security receives new incentive for researchers.

Given this scenario, OpenSats announced a new initiative to fund researchers involved in identifying vulnerabilities. The Code RED program offers resources to developers who find and disclose vulnerabilities, as well as covering expenses related to the use of artificial intelligence tools during analysis.

This move shows that the industry is beginning to direct more resources toward independent audits and research. Finding a vulnerability before an attacker can exploit it can make a significant difference for users and developers.

Despite the high number presented by Bitcoin Red Team, the data does not indicate that thousands of attacks are occurring against the Bitcoin network. These are discoveries in different projects and codebases, and many of them will never lead to actual exploitation.

Nevertheless, the survey reinforces an important message: Bitcoin's security depends not only on the main network, but also on the entire infrastructure built around it . Wallets, libraries, tools, exchanges, and other components continue to require constant audits to reduce ecosystem risks.

 

.......................

How do you rate this article?

3


Kim03
Kim03

I am a content producer. I also publish news content.


Kim Crypto News
Kim Crypto News

Blog about financial news, crypto, bitcoin,

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?