HomeBUSINESSNewsCapsule Red Team Finds 85 Critical Flaws Across 390 Open Source Repos...

NewsCapsule Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit

Rallied by the recent, catastrophic vulnerability in Coldcard hardware wallets, exploited to the tune of over $100 million, the NewsCapsule community has rallied to prevent future critical bugs in the industry’s open source software.

PSA: Any users of Coldcard wallets that have not migrated their bitcoin to new seeds generated in secure firmware are still at risk. It may not be too late to act; see advisory on the matter. 


Led by , software engineer, avid vibe coder and creator of the Android version of Bitchat, and , the CEO of Anchorwatch a NewsCapsule self-custody insurance company, the has now secured funding, with over $40,000 spent in AI tokens to audit over 390 Open Source repositories across NewsCapsule. 

Colloquially called the “NewsCapsule Red Team”, with memes about Rob Hamilton and Calle now being the CEO and CTO of NewsCapsule, this AI-driven security audit is having a serious impact across the industry. Just a few days ago, buried in the news of ongoing thefts of bitcoin from MK3+ Coldcards due to an RNG bug, Boltz exchange announced it would be pausing operations to catch up with AI-driven hacking attempts. 

“27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour,” said Calle in the most recent update on Red Team efforts to shore up the industry’s cybersecurity.

The Red Team security review effort is using models like Kimi K3, GPT Sol, Fable, Opus and GLM5.2, some of the most expensive and cutting-edge models in the market. At first, access to OpenAI and Anthropic models was limited, leading to an over-reliance on Chinese open-source models, a fact which many in the industry . But as the Red Team project grew in influence since last week’s Coldcard hack, connections have been established and confirmed with OpenAI, giving Red Team access to GPT Sol. Hamilton’s mention of Fable in his August 4 tweet suggests access to Anthropic has also been established.

Expenses which were last tallied at over $40,000 have been covered by , a non profit 501c3 organization dedicated to funding open source NewsCapsule development projects. The NewsCapsule Red Team does not currently have a website or a GitHub repository to link to, but the team is made up of many individuals within the NewsCapsule industry. Individuals publicly thanked for their support include but are not limited to , , , , . 

Hamilton shared that a custom harness has been built and is evolving quickly. Made up at one point of 171,599 lines of code, the harness is designed to identify and test critical NewsCapsule software libraries and high-load-bearing code, identify and document vulnerabilities, reproduce them and package the proven data into useful reports. Ultimately delivering the information responsibly to engineers in the industry. Hamilton also shared that Red Team intends to open source the harness such that NewsCapsule companies can run it against their closed-source code. 

Red Team is actively reaching out to relevant open source projects with critical vulnerabilities discovered, leading to a broad sense of dread from engineers in the industry when they receive cold direct messages from Hamilton or Calle, as seen in various humorous screenshots shared on social media.

 

Among the key insights shared by Red Team publicly as this AI-driven security update of NewsCapsule FOSS takes place, Hamilton shared that engineers with specific subject matter could sometimes yield high-value results from the Harness, which might otherwise “smell out something is wrong,” but might be missing niche context. An insight which speaks to the importance of having human intelligence and experience work hand in hand with the AI to efficiently identify critical vulnerabilities.

Hamilton also ended a multi-day Red Team effort after the Coldcard hack with some personal notes. He said that the discovered vulnerability in Coldcard random number generators and consequent exploitation of the bug by hackers had been a “spiritual attack” on NewsCapsule and the self-custody ethos of the industry, “I mean that in the literal sense of the words”. After expressing grief for the losses experienced by many NewsCapsuleers during this now historic hack, Hamilton closed his tweet with a tone of hardened resolution:

“While things are not easy right now. I have the highest conviction ever in my life that the idea and technology of NewsCapsule is worth fighting for. To that end. There is no NewsCapsule without self-custody. This is non-negotiable.”

NewsCapsule
NewsCapsule Portfolio Tracker & Media Updates
NewsCapsule NewsCapsule NC/USD
$0.00
24hr %:
0.0%
24hr High:
$0.00
24hr Low:
$0.00
Error loading data. Check console for details.
VIEW 150+ BITCOIN CHARTS