Bitcoin Red Team generated 6,700 findings in 55 hours of automated scanning covering 425 projects in the Bitcoin ecosystem, with 1,029 classified as critical or high. The campaign, which cost over $20,000, revealed that only 19.5% of scanned projects had a SECURITY.md file and 13.1% had a contact email for vulnerabilities. Public data does not allow determination of how many of these alerts were validated, rejected, or fixed by maintainers, nor calculation of a reliable false-positive rate. The real impact of this campaign on software security therefore remains unknown at this stage.
Source: Read the original article

