Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings

Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings

N
News Editor
2026-08-14 07:32:47
A volunteer-led Bitcoin security effort said Moonshot AI’s Kimi K3 was used to scan 501 open-source Bitcoin projects over two weeks, producing 7,958 findings, with 1,280 rated high-risk or critical. The campaign was organized after a July 30 Coldcard firmware flaw was linked to losses of more than $100 million, with suspected total losses nearing $130 million. On Aug. 13, Bitcoin Red Team member and Cashu founder Calle said the exercise showed how quickly AI can surface long-buried weaknesses in mature codebases. The figures do not mean every issue has been confirmed. At the 108-hour mark, only 24.7% of findings had been dynamically reproduced and 29.4% had been reported to project maintainers, while human validation was still ongoing. Even so, the effort already produced at least one serious real-world case: BTCPay Server said a two-factor authentication bypass reported by Bruno Garcia and Ben Carman had been exploited before it was patched, allowing an attacker to obtain node admin credentials and take control of an attached Lightning wallet. The report also highlighted a policy split in AI access. Rob Hamilton of AnchorWatch said OpenAI blocked his attempt to analyze a publicly disclosed codebase after identity verification, while more than 70 custodians, exchanges, miners and developer groups signed an Aug. 10 public letter urging frontier AI labs to provide access to trusted defenders.

A volunteer-run Bitcoin red team said it used Moonshot AI’s Kimi K3 to scan 501 open-source Bitcoin projects over two weeks, logging 7,958 findings, including 1,280 rated high-risk or critical. On Aug. 13, red team member and Cashu protocol founder Calle posted a progress summary on X that drew nearly 260,000 views.

Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings 2

Calle framed the result bluntly: 「When decades of open-source code collide with two weeks of Kimi K3, the result is that everything is broken and Bitcoin is on fire.」

The effort followed the Coldcard wallet incident

The push began after a July 30 disclosure involving hardware wallet maker Coldcard. According to the article, the device fell back to a predictable software path while generating seed phrases, and the secure chip supplied only 32 bits of entropy. That left an effective key space of roughly 4.3 billion possibilities.

Attackers then drained user wallets in multiple waves. Confirmed losses topped $100 million, and suspected total losses were close to $130 million. Bitcoin Magazine responded with an emergency notice telling users to move funds immediately.

That episode led directly to the creation of the Bitcoin red team. Calle and AnchorWatch CEO Rob Hamilton helped lead the effort, with dozens of contributors taking part. Nonprofit OpenSats reimbursed most of the compute costs, and the group ran what the article described as an AI audit across almost the entire Bitcoin open-source stack.

5,000-plus findings do not mean every issue is confirmed

By Aug. 8, the team had spent hundreds of hours scanning 501 projects. It logged 7,958 findings, with 1,280 marked high-risk or critical.

The article also broke down those numbers. At the 108-hour mark, only 24.7% of findings had been dynamically reproduced, while 29.4% had been reported to maintainers. AI-assisted auditing still produced false positives and duplicates, and manual verification remained in progress.

So the raw count should not be read as a final, fully verified vulnerability ledger. Still, the campaign has already surfaced at least one severe issue that was exploited in the wild.

BTCPay Server said one reported flaw had already been abused

BTCPay Server’s official release notes show that a serious bug reported by red team members Bruno Garcia and Ben Carman involved a two-factor authentication bypass. Before the patch was released, the flaw had already been exploited by a real attacker.

According to the article, the attacker obtained node administration credentials and then gained control over an associated Lightning Network wallet. BTCPay released two security versions in response. The community also set up a recovery bounty for victims, and the foundation added 0.21 BTC to the red team fund.

That response, in the article’s telling, showed maintainers were treating the findings seriously.

Why Kimi K3 became the main tool

The article’s answer was simple: the main U.S. models would not take the job.

Hamilton said that after completing full identity verification, he tried to use an OpenAI model to analyze a publicly disclosed codebase and was refused in less than 20 minutes. A comparison shared by Bitcoin Core contributor PortlandHODL also circulated widely in the community: with the same code sample, a leading U.S. model replied, 「You are right!」 while a Chinese open-source model identified 78 severe vulnerabilities.

Hamilton put his frustration this way: 「I’m basically begging Xi not to let my software get hacked.」

More than 70 organizations signed a public letter

On Aug. 10, more than 70 custodians, exchanges, mining companies and developer organizations signed a public letter from the Bitcoin Policy Institute. The request was for frontier AI labs to provide access to trusted defenders.

Galaxy head of research Alex Thorn wrote in his signatory comment: 「Americans should not be forced to rely on Chinese AI to protect themselves. The red teams need these models.」

The article also added a note of caution. A joint evaluation by the U.K. AI Security Institute and the U.S. CAISI found that Kimi K3 outperformed GLM-5.2 on vulnerability development tests, but still trailed the strongest closed-source U.S. models. In practice, the issue for defenders was not only which model was best, but which one they were actually allowed to use.

One prompt can shorten the path from bug discovery to exploitation

Calle’s key warning was this: 「In the past, finding a buffer overflow was not enough. You still needed a skilled hacker to turn it into a usable attack. Today, all it takes is one prompt.」

The article tied that shift to three immediate conclusions. Old projects with no active maintenance should be treated as suspect by default. Response speed to vulnerability reports is now a visible measure of project health, and Calle said, 「Move fast during this period.」 He also singled out the Lightning Network, saying it was 「more broken than typical projects,」 and that related wallet balances and channel balances were worth checking more closely.

As for the 501 scanned projects, the article said the low-hanging fruit had largely been picked and the baseline sweep of the Bitcoin open-source ecosystem was done. Calle’s broader point was that Bitcoin was only the first system to hit this wall. If one prompt can turn an old bug into a weapon, any software project leaning on the comfort of 「nobody found it for years」 may be next.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
380

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.