Bitcoin Red Team expanded its AI-assisted audit to 501 Bitcoin-related open-source projects, and logged 7,958 potential security findings after 108 hours of work.
The scale is striking, but the headline number needs context. Of the 7,958 findings, 1,280 were classified as high or critical, while only 24.7% were dynamically reproduced and 29.4% reported upstream at the latest tally. That means the dataset is better viewed as a large security triage queue than as proof of thousands of exploitable Bitcoin vulnerabilities.
The campaign nevertheless produced real-world fixes. BTCPay Server’s Aug. 7 release of version 2.4.2 warned of a critical vulnerability that was being actively exploited and credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting it. The update fixed a TOTP two-factor authentication bypass through Greenfield Basic Authentication and disabled Basic Authentication by default shortly after account creation.
The operational impact was big enough that OpenSats disclosed it had been running the affected BTCPay Server and LND stack. The nonprofit said it updated quickly, lost no donated funds and temporarily disabled Lightning donations as a precaution.
Kimi K3 turns code review into a scaling problem
The audit also sheds some light on why AI-assisted security research is changing the economics of vulnerability discovery. Calle, a pseudonymous developer involved in Bitcoin Red Team, said the group used Moonshot AI’s Kimi K3 to work through a large portion of the Bitcoin open-source ecosystem in roughly two weeks.
Independent testing suggests Kimi K3 is capable but not infallible. A joint assessment by the UK AI Security Institute and U. CAISI gave Kimi K3 a 32% score on ExploitBench, ahead of GLM-5.2’s 24%. Yet it achieved arbitrary code execution on zero of 41 samples, compared with an average of 20 successful samples for the most cyber-capable models tested.
(Source: AISI)
That gap matters. AI can dramatically increase the number of suspicious code paths researchers examine, but human verification still determines whether a report is exploitable, duplicated, incorrectly scored or harmless.
Bitcoin security enters a faster patch cycle
The bigger story may therefore be less about 7,958 individual findings and more about the speed mismatch AI creates between discovery and remediation.
OpenSats already launched a dedicated Red Team Fund that can reimburse researchers for LLM token costs. A coalition of more than 40 digital-asset organizations also called for vetted open-source defenders to receive controlled access to frontier AI models.
For users, this is not evidence that Bitcoin’s consensus protocol is broken. The more immediate risk lies in the surrounding software stack—wallets, Lightning infrastructure, payment servers and older libraries—where a single overlooked authentication or key-management flaw can translate directly into lost funds.
AI is making those weaknesses cheaper to find. The next security advantage may belong to projects that can verify, patch and ship fixes just as quickly.




Be the first to comment