Bitcoin software faces AI-driven security pressure as Bitcoin Red Team races to find flaws

Bitcoin software faces AI-driven security pressure as Bitcoin Red Team races to find flaws

N
News Editor
2026-08-22 15:32:52
Artificial intelligence is lowering the barrier to offensive cyber capabilities, and Bitcoin developers say that shift is turning wallets, apps, exchanges, Lightning software, and other tools around Bitcoin into more attractive targets. In an interview with Decrypt, pseudonymous developer Calle said the Bitcoin Red Team was formed as an emergency effort to identify AI-assisted threats across the broader Bitcoin ecosystem before attackers can use them. According to Calle, the volunteer group has about 20 to 25 members, including pseudonymous contributors such as Stu, Talip, and thesimplekid, along with developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Vinteum Bitcoin R&D Center board member Bruno Garcia. Calle said the group has not found issues in the Bitcoin protocol itself. The concern is centered on surrounding software that users rely on to transact with Bitcoin. Calle also said the team uses Chinese AI models far more often than U.S. models because guardrails on American systems can block security research. He argued that AI has weakened the information advantage that once kept some vulnerabilities out of reach for less-skilled attackers, and said crypto may be feeling that pressure earlier than other sectors because internet money presents a direct financial target.

Artificial intelligence is putting advanced hacking capabilities in the hands of people with little cybersecurity experience, pushing crypto developers into a race to uncover weaknesses before attackers exploit them.

Bitcoin software faces AI-driven security pressure as Bitcoin Red Team races to find flaws 2

One of the groups taking on that work is the Bitcoin Red Team. Pseudonymous member and Bitcoin software developer Calle told Decrypt the team was formed as an emergency effort to identify AI-assisted security threats across the Bitcoin ecosystem.

「At this point, it is a question about time,」 Calle said. Calle also helps maintain the open-source protocol Cashu. 「The reason why the Bitcoin Red Team exists right now is because we need to get ahead of the attackers as fast as possible.」

A volunteer group of roughly 20 to 25 people

The Bitcoin Red Team has about 20 to 25 volunteers, according to Calle. Many prefer to stay pseudonymous, including Bitcoin privacy protocol developers Stu and Talip, as well as fellow Cashu developer thesimplekid.

Other members include Bitcoin developers Ben Carmen, Daniela Brozzoni, and James O'Beirne, along with Bruno Garcia, a board member at the Vinteum Bitcoin R&D Center.

In an August 4, 2026 update, Rob Hamilton said the group had been working around the clock and had spent about $20,000 across different services so far. He added that funding was secured and extra donations were not necessary because the bill was already covered.

Calle said the team began to take shape after AnchorWatch CEO Rob Hamilton started reviewing Bitcoin projects following the Coldcard air-gapped wallet hack.

The concern is the software around Bitcoin, not the protocol itself

Calle said the group has found no issues in the Bitcoin protocol itself. The risk, in his view, sits in the applications, wallets, services, and other software built around Bitcoin.

「Although Bitcoin itself is secure, the software that we're using to transact with Bitcoin may not be, and that is what most people interface with anyway,」 he said.

The Coldcard exploit, attacks on other Bitcoin services, and the release of more powerful Chinese AI models pushed Calle and other security researchers to join the effort and move quickly.

「I think the arrival of Kimi K3 has also caused a lot of chaos in the cybersecurity realm because it gave attackers as well as defenders unprecedented power,」 he said.

Proactive scans across the open-source ecosystem

As Calle described it, the Red Team receives requests from Bitcoin projects that want security scans, but it also hunts for vulnerabilities on its own.

「We get a bunch of inbound requests from projects that want to be scanned, but we act proactively, and we've covered almost the entire significant open-source ecosystem by our own sweeps already,」 Calle said. 「So even if you come and ask us to scan your project, we've probably scanned it already.」

The team shares its findings with affected developers and uses their feedback to refine vulnerability classifications and severity ratings.

Why the group leans on Chinese AI models

Calle said Chinese AI models are used far more than U.S. models in the team's security work because guardrails on American models can interfere with cybersecurity research.

「It's not even close,」 he said.

In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation. In April, the Trump administration warned that Chinese entities were running similar campaigns on an 「industrial scale.」

Even so, Calle said U.S. frontier models remain arguably stronger overall, but their restrictions reduce their value for security-sensitive work.

「Although U.S.-based frontier models are still arguably more intelligent than any other models out there in the world, they all come with heavy guardrailing, which limits their use, especially in the cybersecurity realm,」 he said.

Before joining the Red Team, Calle said he had already run into those limits. He said U.S. models sometimes refused to help identify vulnerabilities and in some cases would not assist with fixing flaws developers had already found, which led him to shift to Chinese AI models.

「Bitcoin is burning」

Earlier this month, Calle described the growing security threat facing Bitcoin software as 「Bitcoin is burning.」 He was referring not to the Bitcoin protocol itself, but to the wider software stack around it, including wallets, exchanges, Lightning implementations, and other Bitcoin-related tools.

Calle said he believes attackers are already using AI to find and exploit vulnerabilities, though he avoids discussing methods in detail because he does not want to give malicious hackers new ideas.

He also argued that AI is erasing the information advantage that once kept some software flaws out of reach for less-skilled attackers.

「I think that there are no secrets anymore in software,」 Calle said. 「There is no information asymmetry that was previously being used to kind of create security theater or security through obscurity. Those times are over.」

AI has also lowered the technical barrier to exploiting vulnerable software, he said.

「Simple exploits can now be completed end to end by someone who doesn't know how to do it without AI,」 Calle said. 「So AI gave people a form of power that has completely changed the playing field.」

Why crypto may be hit earlier than other sectors

Calle said Bitcoin may be facing this shift before other industries because attackers have a direct financial incentive to target cryptocurrency systems.

「The first thing that, as an attacker, you would want to attack is internet money,」 he said. 「So we are the beginning of a larger change in society or in computer systems in general, and I'm convinced that other industries will experience the same thing as we do right now later.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
5000

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.