Artificial intelligence is lowering the barrier to entry for cyberattacks, and Bitcoin Red Team was formed to help Bitcoin projects get ahead of that shift. Calle, an anonymous Bitcoin software developer and member of the group, said the team has 20 to 25 volunteers and focuses on wallets, applications, services and other third-party software built on Bitcoin rather than the base protocol itself.
Calle said the group has already covered nearly every important open-source project in the Bitcoin ecosystem through proactive scans, while also taking requests from projects that ask for reviews. He added that Chinese AI models are used more often in this work because US models tend to block cybersecurity-related tasks.
He also said that AI is reducing the need for deep technical knowledge, making simple exploit workflows accessible to people who would not previously have been able to carry them out. In his view, Bitcoin and other crypto systems are likely to feel that change earlier than most industries because attackers have a direct financial incentive.
AI is lowering the bar for cyberattacks, and Bitcoin developers are racing to find weaknesses before attackers do.
Bitcoin Red Team was formed to respond to that risk inside the Bitcoin ecosystem, according to Calle, an anonymous member of the group and a Bitcoin software developer. He said the team exists so it can stay ahead of AI-assisted threats as much as possible.
"Now, it is only a matter of time," Calle told Decrypt. "Bitcoin Red Team was formed because we want to stay as far ahead of attackers as we can."
The group has 20 to 25 volunteers, Calle said. Many of them are anonymous, including Bitcoin privacy protocol developers Stu and Talip, as well as thesimplekid, who also works on Cashu. Other members include Bitcoin developers Ben Carmen, Daniela Brozzoni and James O'Beirne, along with Bruno Garcia, a board member at the Bitcoin research center Vinteum.
Calle said AnchorWatch CEO Rob Hamilton began reviewing Bitcoin projects after the Coldcard offline hardware wallet was hacked, and Bitcoin Red Team took shape in that context.
He stressed that the team has not found a problem in Bitcoin's base protocol. The risks, he said, are concentrated in wallets, apps, services and other third-party software built on top of Bitcoin.
"The base layer of Bitcoin is secure, but the software people actually use to transact in Bitcoin may not be," he said. "And that is what most users interact with."
Coldcard being hacked, several Bitcoin-related services being attacked, and the arrival of more capable Chinese AI models pushed Calle and other security researchers to move faster.
"I think Kimi K3 has brought a lot of turbulence to cybersecurity, and it gives both attackers and defenders unprecedented capabilities," he said.
Bitcoin Red Team takes scans from projects that request them, but it also looks for flaws on its own. Calle said the group has already covered nearly every important open-source project in the ecosystem through its own work.
"A lot of projects come to us and ask for a scan, but we also go out and do our own searches. Through that work, we have covered almost all of the important open-source projects in the ecosystem. In other words, by the time some projects ask us for a scan, we may already have scanned them," he said.
He added that Chinese AI models are used far more often than US models in this work because US systems tend to block cybersecurity-related tasks.
"The gap is very obvious," he said.
Calle said US frontier models are still ahead in overall capability, but strict safety limits reduce their usefulness in security work. Before joining the red team, he had already run into those limits himself. US models would sometimes refuse to help find vulnerabilities, and even when a developer had already confirmed a flaw, they would not help with remediation. That pushed him toward Chinese AI models instead.
Earlier this month, Calle described the pressure on Bitcoin software as "Bitcoin is burning." In that context, Bitcoin refers to wallets, exchanges, Lightning Network implementations and the broader software stack built around the network.
He believes attackers are already using AI to find and exploit flaws, but he declined to go into detail so as not to help malicious hackers.
Calle also warned that software vulnerabilities used to be protected by information barriers that kept less-skilled attackers out, but AI is removing that barrier.
"There are no secrets left in software," he said. "The old model of security through obscurity, of relying on hidden details, no longer works. That era is over."
AI is also lowering the technical threshold for exploiting bugs.
"Now, someone without that technical background can use AI to carry out a simple exploit from start to finish," Calle said. "That ability completely changes the balance between attackers and defenders."
In his view, crypto is an obvious target because it can generate direct financial gain, so Bitcoin is likely to feel this shift before other industries do.
"Attackers go after internet money first," he said. "We are at the beginning of a major shift across the computing industry, and I am sure other sectors will eventually face the same security problems we are dealing with now."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.