Bitcoin red team says Kimi K3 scanned 501 projects in two weeks and flagged 1,280 high-risk findings
A volunteer-led Bitcoin security effort said Moonshot AI’s Kimi K3 was used to scan 501 open-source Bitcoin projects over two weeks, producing 7,958 findings, with 1,280 rated high-risk or critical. The campaign was organized after a July 30 Coldcard firmware flaw was linked to losses of more than $100 million, with suspected total losses nearing $130 million. On Aug. 13, Bitcoin Red Team member and Cashu founder Calle said the exercise showed how quickly AI can surface long-buried weaknesses in mature codebases. The figures do not mean every issue has been confirmed. At the 108-hour mark, only 24.7% of findings had been dynamically reproduced and 29.4% had been reported to project maintainers, while human validation was still ongoing. Even so, the effort already produced at least one serious real-world case: BTCPay Server said a two-factor authentication bypass reported by Bruno Garcia and Ben Carman had been exploited before it was patched, allowing an attacker to obtain node admin credentials and take control of an attached Lightning wallet. The report also highlighted a policy split in AI access. Rob Hamilton of AnchorWatch said OpenAI blocked his attempt to analyze a publicly disclosed codebase after identity verification, while more than 70 custodians, exchanges, miners and developer groups signed an Aug. 10 public letter urging frontier AI labs to provide access to trusted defenders.








