In brief

  • The Bitcoin Red Team is using Chinese AI models to search Bitcoin projects for security flaws.
  • Calle said developers have confirmed numerous critical and high-severity vulnerabilities.
  • They warned that unmaintained projects should not be trusted.

The Bitcoin Red Team is using Chinese AI models to search nearly the entire Bitcoin open-source ecosystem for security flaws, according to pseudonymous developer and Red Team lead Calle.

The volunteer group combines AI tools with human review to examine wallets, Lightning applications, software libraries, and other Bitcoin projects. Researchers privately report credible findings to developers so the flaws can be fixed before details are released.

Myriad: Bitcoin's next move? Click to make your prediction.
Myriad: Bitcoin's next move? Click to make your prediction.

“We’re experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3,” Calle wrote Thursday on X. “Everything is broken, Bitcoin is burning.”

Kimi K3 is an AI model from Chinese startup Moonshot AI that developers can download and run on their own systems. It can analyze large codebases and complete lengthy software tasks with little supervision.

The Bitcoin Red Team has also used Chinese developer Z.ai’s GLM 5.2, as well as models from OpenAI and Anthropic. American models, though, come with limitations, and developers frequently run up against restrictions imposed by OpenAI and Anthropic when doing security research. “Red team rugged by OpenAI cyber again,” Calle posted earlier this week. “Don’t like asking for permission. Loading up Kiimi K3.”

Nevertheless, the developer noted that the team is making progress, even if slow and painful.

“We’ve basically completed a basic scan of virtually the entirety of Bitcoin open source,” Calle wrote. “The low hanging fruit is done.”

In August, the group reported filing 4,962 findings across 390 projects, including 85 rated critical and 635 rated high severity. Calle said developers had confirmed “a ton of real critical and high vulnerabilities,” though the group has not named the affected projects or released technical details.

“Response speed is very different across projects and shows how healthy each project is,” they wrote. “I recommend acting fast these days.”

Lightning software, which supports faster and cheaper Bitcoin payments, was particularly difficult to review because of its complexity, Calle said, calling it “more broken than the average.”

“Those projects that started AI audits months ago are in a completely different position than those who didn’t,” he wrote. “Projects need their own AI audit pipeline going into the future.”

Calle also warned against relying on unmaintained projects and said AI has made it more stressful for developers to keep their software secure.

The Bitcoin Red Team is not alone. Last month, Hugging Face used China’s GLM 5.2 to investigate a breach after OpenAI models hacked into its systems and U.S. commercial models refused to analyze the attack logs.

Despite saying Bitcoin is “burning,” Calle argued that the audits are making its software stronger.

“Bitcoin is the obvious first target, but the rest of the world will follow shortly,” Calle wrote. “Sometimes old things need to burn so new things can grow on healthy soil.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.