Bitcoin Red Team's AI-assisted security sweep of 501 open-source projects logged 7,958 potential vulnerabilities, with 1,280 rated high or critical severity.
Bitcoin Red Team's AI-assisted security sweep of 501 open-source projects logged 7,958 potential vulnerabilities, with 1,280 rated high or critical severity.

Bitcoin Red Team's AI-assisted security sweep of 501 open-source projects logged 7,958 potential vulnerabilities, with 1,280 rated high or critical severity.
Bitcoin Red Team logged 7,958 potential security issues across 501 open-source projects after 108 hours of AI-assisted review, with 1,280 findings classified as high or critical severity.
"Everything is broken, bitcoin is burning," Calle, a pseudonymous Bitcoin developer leading the effort, said on X on Aug. 13, describing the collision between years of accumulated open-source code and frontier AI models.
The team dynamically reproduced 24.7 percent of all findings and reported 29.4 percent upstream to project maintainers at the 108-hour mark. Moonshot AI's Kimi K3 served as the primary scanning model, scoring 32 percent on ExploitBench in a joint U.K. AI Security Institute and U.S. CAISI assessment.
The vulnerabilities cluster in wallets, Lightning infrastructure, and payment software rather than Bitcoin's base consensus protocol. BTCPay Server already patched a critical two-factor authentication bypass in v2.4.2 after attackers used it to access connected Lightning wallets, and released v2.4.3-rc4 on Aug. 14 addressing additional reports.
The audit expanded from an earlier sweep that found 4,962 potential issues across 390 projects, including 720 rated high or critical. The newer tally reflects a materially broader review after the July 30 Coldcard firmware exploit that stole well over $100 million in bitcoin from seeds generated with insufficient entropy.
Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance company, said he was blocked from further analysis on a codebase he had already responsibly disclosed after integrating OpenAI's trusted cyber program. "It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure," Hamilton wrote on X.
Francis Pouliot, founder of Bull Bitcoin, detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked American models he pays for to review the same patch, they refused.
Calle argued that unmaintained projects should be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses. He also said response time is becoming a useful indicator of project health, and that maintainers will increasingly need their own continuing AI audit pipelines.
OpenSats has created a fast-tracked red-teaming grant route focused partly on reimbursing researchers for LLM costs. More than 70 organizations signed a Bitcoin Policy Institute open letter on Aug. 10 calling on frontier AI labs to establish trusted-access programs for qualified open-source defenders.
Alex Thorn, Head of Firmwide Research at Galaxy, signed the letter. "Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks," he wrote on X.
The next phase is likely to move more slowly than the initial sweep. Automated discovery can scale quickly, while reproduction, responsible disclosure, patch development, and regression testing require more time. For Bitcoin users, the immediate security concern centers on wallets, Lightning infrastructure, payment software, and libraries carrying older or lightly reviewed code.
This article is for informational purposes only and does not constitute investment advice.