BackRob Hamilton

Rob Hamilton

Bitcoin
2026-08-14 07:32:47

Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings

A volunteer-led Bitcoin security effort said Moonshot AI’s Kimi K3 was used to scan 501 open-source Bitcoin projects over two weeks, producing 7,958 findings, with 1,280 rated high-risk or critical. The campaign was organized after a July 30 Coldcard firmware flaw was linked to losses of more than $100 million, with suspected total losses nearing $130 million. On Aug. 13, Bitcoin Red Team member and Cashu founder Calle said the exercise showed how quickly AI can surface long-buried weaknesses in mature codebases. The figures do not mean every issue has been confirmed. At the 108-hour mark, only 24.7% of findings had been dynamically reproduced and 29.4% had been reported to project maintainers, while human validation was still ongoing. Even so, the effort already produced at least one serious real-world case: BTCPay Server said a two-factor authentication bypass reported by Bruno Garcia and Ben Carman had been exploited before it was patched, allowing an attacker to obtain node admin credentials and take control of an attached Lightning wallet. The report also highlighted a policy split in AI access. Rob Hamilton of AnchorWatch said OpenAI blocked his attempt to analyze a publicly disclosed codebase after identity verification, while more than 70 custodians, exchanges, miners and developer groups signed an Aug. 10 public letter urging frontier AI labs to provide access to trusted defenders.

380
Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings
Bitcoin
2026-08-14 07:22:00

AI is reshaping Bitcoin security, and Chinese open-source models are filling a key gap

Large language models are moving from the edge of crypto security into its core. In Bitcoin, that shift is showing up on both sides of the fight: attackers are using AI to speed up code review, vulnerability discovery, and exploit development, while defenders are turning to the same tools to audit software and triage risks at scale. Recent incidents involving hardware wallet maker Coldcard and non-custodial Bitcoin swap provider Boltz have sharpened those concerns, with the latter suspending Bitcoin swap services indefinitely after saying AI-assisted attacks were outpacing its ability to patch flaws. Security teams are responding in kind. Bitcoin Red Team, a volunteer group led by Cashu founder and Bitcoin open-source developer Calle and AnchorWatch CEO Rob Hamilton, said it scanned 390 Bitcoin-related open-source projects in less than 30 hours and logged 4,962 findings, including 85 critical and 635 high-severity issues. The group is using Chinese AI models including Moonshot AI’s Kimi K3 and Zhipu AI’s GLM 5.2, reflecting a broader complaint from researchers that restrictions imposed by some U.S. model providers can block legitimate security work. That debate has now reached policy circles, with the Bitcoin Policy Institute and dozens of crypto firms urging frontier AI labs to provide trusted, long-term access for open-source defenders.

420
AI is reshaping Bitcoin security, and Chinese open-source models are filling a key gap
Bitcoin
2026-08-13 16:18:45

Bitcoin Security Researchers Say Restricted U.S. AI Models Are Falling Behind Chinese Open Models

Bitcoin security researchers, company founders, and policy advocates are publicly warning that restrictions on leading U.S. AI systems are making legitimate defensive cybersecurity work harder, while Chinese open-source models are producing usable results. Rob Hamilton of AnchorWatch said OpenAI blocked him from analyzing a codebase he had already responsibly disclosed, even after he joined the company’s trusted cyber program and had completed KYC months earlier. He later said he was cut off again within 19 minutes after receiving access to OpenAI’s Daybreak Blue cyber model. Francis Pouliot of Bull Bitcoin said Chinese open models helped identify and patch a money-stealing exploit in a project he was auditing, while American models he pays for refused to review the same patch. Similar complaints came from Bitcoin Core contributor PortlandHODL and Galaxy research head Alex Thorn, who backed a Bitcoin Policy Institute open letter calling for trusted access to frontier AI models for qualified open-source defenders. Published on August 10 and signed by more than 70 digital-asset organizations, the letter asks AI labs for early access to cyber-capable systems, enough compute, secure code-review environments, and direct contact with lab security teams. The pressure intensified after a Coldcard firmware flaw, exploited from July 30, led to the theft of well over $100 million in bitcoin. Since then, the volunteer Bitcoin Red Team says it has scanned 501 projects and logged 7,958 findings, including 1,280 high or critical issues, with most compute spend going to Chinese open-weight models.

510
Bitcoin Security Researchers Say Restricted U.S. AI Models Are Falling Behind Chinese Open Models
Bitcoin secur
2026-08-08 17:32:50

Bitcoin Red Team Scans 150 Codebases, Discloses More Than Ten Vulnerabilities

According to ChainCatcher, the Bitcoin Red Team volunteer security initiative has scanned about 150 Bitcoin codebases and disclosed more than ten vulnerabilities. The team is developing an open-source AI platform to audit Bitcoin software, spanning wallets, cryptographic libraries, infrastructure, and other projects. AnchorWatch CEO Rob Hamilton said the team has spent approximately $20,000 on various AI services so far, using Kimi K3, OpenAI's GPT Sol, Anthropic's Claude Fable and Opus, and Z.ai's GLM 5.2 to identify vulnerabilities and generate documentation. A pseudonymous Bitcoin developer called Calle revealed that in the past 12 hours, the team has reported critical vulnerabilities to multiple projects, with each person finding about one critical vulnerability per hour on average and daily spending around $10,000. The team has not disclosed the affected projects or vulnerability details.

560
Bitcoin Red Team Scans 150 Codebases, Discloses More Than Ten Vulnerabilities
Bitcoin
2026-08-08 17:31:03

Bitcoin Red Team Says AI Scans Found More Than a Dozen Vulnerabilities Across 150 Repositories

A volunteer security effort focused on Bitcoin says it has used several frontier AI models to scan 150 repositories and uncover more than a dozen vulnerabilities, highlighting how artificial intelligence is being used more aggressively in blockchain security reviews. AnchorWatch CEO Rob Hamilton said on X earlier this week that the group has spent about $20,000 on AI services while building what he described as a "Bitcoin red team" platform, adding that funding is already secured and donations are not needed. Hamilton said the initiative relies on Kimi K3, OpenAI’s GPT Sol, Anthropic’s Claude Fable and Opus models, and Z.ai’s GLM 5.2 to detect vulnerabilities and produce supporting documentation. He also said the team received help from OpenAI to get a system called Cyber Harness running, describing it as a more expensive scan that has already produced results for key parts of the Bitcoin ecosystem. Pseudonymous developer Calle said the group has built multiple AI-powered review systems for wallets, cryptographic libraries, infrastructure, and other Bitcoin projects, and claimed the team is finding roughly one critical exploit per hour per person. The team said it reported critical vulnerabilities to several projects in the last 12 hours, but did not name the affected projects or disclose technical details.

570
Bitcoin Red Team Says AI Scans Found More Than a Dozen Vulnerabilities Across 150 Repositories
Bitcoin
2026-08-08 10:40:10

Kimi K3 flags 4,962 flaws in 24-hour Bitcoin ecosystem audit as Coldcard fallout deepens

Bitcoin developers say an AI-assisted security sweep has exposed thousands of weaknesses across the broader ecosystem just as the fallout from the Coldcard wallet exploit continues to unsettle users and traders. A volunteer team said it scanned about 390 Bitcoin-related projects in roughly 24 hours and found 4,962 security issues, including 85 critical bugs and 635 high-severity flaws, calling the state of ecosystem security "extremely bad." The group, now 16 people working in shifts around the clock, is using Moonshot’s open-weight Kimi K3 model, with daily compute costs of about $10,000 covered by OpenSats. At the same time, Coldcard is still urging users to move funds after an exploit tied to a five-year-old key-generation defect led to the theft of nearly 2,000 BTC from more than 5,200 addresses over several days. One wallet linked to the attacker still holds about $36 million in bitcoin, while on-chain messages sent to that address include pleas for the funds to be returned and at least one message offering laundering services for a 10% fee. The overlap between AI-powered defense and AI-assisted exploitation has become a central concern.

510
Kimi K3 flags 4,962 flaws in 24-hour Bitcoin ecosystem audit as Coldcard fallout deepens
Bitcoin
2026-08-07 11:17:54

AI-led audit flags 85 critical bugs across 390 Bitcoin-related projects

An AI-assisted security review conducted by a 16-member group of Bitcoin developers has identified 85 critical vulnerabilities across 390 Bitcoin-related projects, according to Blockcast. The effort also logged 4,962 potential risks in total, including 635 high-risk issues, after examining Bitcoin wallets, cryptographic libraries, and other infrastructure. Calle, the pseudonymous developer behind the e-cash protocol Cashu who coordinated the effort, said the findings showed the situation was "very bad." Rob Hamilton, the developer who built the automated auditing system, said the main obstacle is no longer finding flaws but securely and accurately reporting sensitive vulnerability details to the right project maintainers. He described the current system as a "1.0 version" despite its ability to uncover serious defects. The report also pointed to the recent Coldcard hack as a reminder of how dangerous long-standing software flaws can be. The incident, which broke out on July 30, has led to $114 million in user assets being stolen. According to the report, the breach traced back to a firmware vulnerability that had existed since 2021, showing that even funds kept in cold wallets can remain exposed if the underlying software is flawed.

560
AI-led audit flags 85 critical bugs across 390 Bitcoin-related projects
Bitcoin Red T
2026-08-06 01:16:58

Bitcoin Red Team Flags Nearly 5,000 Potential Issues in 390 Projects Within 29.8 Hours

Bitcoin Red Team, an all-volunteer security group, said it found nearly 5,000 potential issues during a rapid AI-assisted audit of Bitcoin ecosystem projects. The team consists of 16 volunteers, and its ranks include AnchorWatch CEO Rob Hamilton as well as bitcoin developer Calle. Calle explained that the group pairs AI tools with manual review to scan Bitcoin-related open-source codebases for vulnerabilities. That workflow produced an average of about one critical vulnerability per person per hour. Within 29.8 hours of the audit beginning, the team had reviewed 390 projects and logged 4,962 potential issues. Of those, 720 were classified as high severity or critical, and 21.4% of the findings have been reproduced so far. The remaining 78.6% have not yet been reproduced. The audit started a few days after the Coldcard hardware wallet incident, a security event in which more than $100 million in bitcoin was stolen. The numbers were relayed by Calle in his disclosure.

610
Bitcoin Red Team Flags Nearly 5,000 Potential Issues in 390 Projects Within 29.8 Hours