The Bitcoin Red Team is using Chinese AI models to look for security flaws across nearly the entire Bitcoin open-source ecosystem, according to pseudonymous developer and Red Team lead Calle. The effort covers wallets, Lightning applications, software libraries, and other Bitcoin projects.

The volunteer group combines AI tools with human review. When researchers find credible issues, they report them privately to developers so fixes can be made before any details are released.
Chinese models gained ground as U.S. tools hit research limits
On Thursday, Calle wrote on X: 「We’re experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3. Everything is broken, Bitcoin is burning.」
Kimi K3 is an AI model from Chinese startup Moonshot AI. Developers can download it and run it on their own systems. The model can work through large codebases and handle long software tasks with limited supervision, according to the report.
The Bitcoin Red Team has also used Chinese developer Z.ai’s GLM 5.2, along with models from OpenAI and Anthropic. Calle said the American models come with restrictions, and that the team repeatedly runs into limits imposed by OpenAI and Anthropic while doing security research. Earlier this week, he posted on X: 「Red team rugged by OpenAI cyber again. Don’t like asking for permission. Loading up Kimi K3.」
Even so, Calle said the team is moving forward, though slowly and with difficulty.
4,962 findings filed across 390 projects in August
Calle wrote that the group has 「basically completed a basic scan of virtually the entirety of Bitcoin open source」 and that 「the low hanging fruit is done.」
In August, the group reported filing 4,962 findings across 390 projects. Among them, 85 were rated critical and 635 high severity. Calle said developers had confirmed 「a ton of real critical and high vulnerabilities,」 but the group has not named the affected projects or published technical details.
He also wrote that response times vary widely from one project to another and said that difference shows how healthy each project is. 「I recommend acting fast these days,」 he added.
Lightning software proved harder to review
Calle said Lightning software, which supports faster and cheaper Bitcoin payments, has been particularly difficult to audit because of its complexity. He described it as 「more broken than the average.」
Projects that started AI audits months ago are now in a very different position from those that did not, he wrote. In his view, projects will need their own AI audit pipeline going forward.
Calle also warned against relying on unmaintained projects and said AI has made it more stressful for developers to keep software secure.
Not an isolated case
The Bitcoin Red Team is not the only group taking this route. Last month, Hugging Face used China’s GLM 5.2 to investigate a breach after OpenAI models hacked into its systems and U.S. commercial models refused to analyze the attack logs, the report said.
Despite saying Bitcoin is 「burning,」 Calle argued that the audit work is making Bitcoin software stronger.
「Bitcoin is the obvious first target, but the rest of the world will follow shortly,」 he wrote. 「Sometimes old things need to burn so new things can grow on healthy soil.」

