Bitcoin Red Team uses Chinese AI models to scan the open-source stack for flaws

Bitcoin Red Team uses Chinese AI models to scan the open-source stack for flaws

N
News Editor
2026-08-13 22:36:07
The Bitcoin Red Team, a volunteer security group, is using Chinese AI models alongside human review to search for vulnerabilities across nearly the entire Bitcoin open-source ecosystem, according to pseudonymous developer and team lead Calle. The work covers wallets, Lightning applications, software libraries, and other Bitcoin projects, with credible findings privately disclosed so developers can patch issues before details are published. Calle said the team has used Moonshot AI’s Kimi K3, Z.ai’s GLM 5.2, and models from OpenAI and Anthropic. He argued that U.S. models often impose restrictions that get in the way of security research, prompting the team to lean more heavily on Chinese alternatives that can be run locally. The group said it has completed a basic scan of virtually all Bitcoin open-source code and, in August alone, filed 4,962 findings across 390 projects. Of those, 85 were rated critical and 635 high severity. Calle said developers had confirmed many real critical and high-risk issues, though the team has not identified affected projects or released technical details. He also said Lightning software has been especially hard to review because of its complexity, and warned that projects without their own AI audit pipeline may be falling behind.
BitcoinAI security auditsKimi K3GLM 5.2Open-source securityLightning NetworkMoonshot AIBitcoin Red Team

The Bitcoin Red Team is using Chinese AI models to look for security flaws across nearly the entire Bitcoin open-source ecosystem, according to pseudonymous developer and Red Team lead Calle. The effort covers wallets, Lightning applications, software libraries, and other Bitcoin projects.

Bitcoin Red Team uses Chinese AI models to scan the open-source stack for flaws 2

The volunteer group combines AI tools with human review. When researchers find credible issues, they report them privately to developers so fixes can be made before any details are released.

Chinese models gained ground as U.S. tools hit research limits

On Thursday, Calle wrote on X: 「We’re experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3. Everything is broken, Bitcoin is burning.」

Kimi K3 is an AI model from Chinese startup Moonshot AI. Developers can download it and run it on their own systems. The model can work through large codebases and handle long software tasks with limited supervision, according to the report.

The Bitcoin Red Team has also used Chinese developer Z.ai’s GLM 5.2, along with models from OpenAI and Anthropic. Calle said the American models come with restrictions, and that the team repeatedly runs into limits imposed by OpenAI and Anthropic while doing security research. Earlier this week, he posted on X: 「Red team rugged by OpenAI cyber again. Don’t like asking for permission. Loading up Kimi K3.」

Even so, Calle said the team is moving forward, though slowly and with difficulty.

4,962 findings filed across 390 projects in August

Calle wrote that the group has 「basically completed a basic scan of virtually the entirety of Bitcoin open source」 and that 「the low hanging fruit is done.」

In August, the group reported filing 4,962 findings across 390 projects. Among them, 85 were rated critical and 635 high severity. Calle said developers had confirmed 「a ton of real critical and high vulnerabilities,」 but the group has not named the affected projects or published technical details.

He also wrote that response times vary widely from one project to another and said that difference shows how healthy each project is. 「I recommend acting fast these days,」 he added.

Lightning software proved harder to review

Calle said Lightning software, which supports faster and cheaper Bitcoin payments, has been particularly difficult to audit because of its complexity. He described it as 「more broken than the average.」

Projects that started AI audits months ago are now in a very different position from those that did not, he wrote. In his view, projects will need their own AI audit pipeline going forward.

Calle also warned against relying on unmaintained projects and said AI has made it more stressful for developers to keep software secure.

Not an isolated case

The Bitcoin Red Team is not the only group taking this route. Last month, Hugging Face used China’s GLM 5.2 to investigate a breach after OpenAI models hacked into its systems and U.S. commercial models refused to analyze the attack logs, the report said.

Despite saying Bitcoin is 「burning,」 Calle argued that the audit work is making Bitcoin software stronger.

「Bitcoin is the obvious first target, but the rest of the world will follow shortly,」 he wrote. 「Sometimes old things need to burn so new things can grow on healthy soil.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.