Summary

  • The Bitcoin Red Team is employing Chinese AI tools to identify security vulnerabilities within Bitcoin projects.
  • Calle has reported that developers have recognized several severe vulnerabilities.
  • They cautioned that projects lacking maintenance should be approached with skepticism.

The Bitcoin Red Team is harnessing AI models from China to scan the vast Bitcoin open-source ecosystem for security issues, as stated by the pseudonymous developer and leader of the Red Team, Calle.

This group of volunteers is utilizing AI technology alongside human expertise to scrutinize various Bitcoin projects, including wallets, Lightning applications, software libraries, and more. They privately share their credible discoveries with developers to enable timely fixes before any public disclosure.

Myriad: What’s Bitcoin’s upcoming strategy? Click to share your thoughts.

“We’re witnessing a significant clash between years of human-created open-source errors and two weeks of Kimi K3,” Calle remarked on X. “Everything is malfunctioning, and Bitcoin is suffering.”

Kimi K3, an AI tool from the Chinese startup Moonshot AI, can be downloaded by developers for local use, allowing it to analyze extensive codebases and manage complex software tasks with minimal oversight.

Additionally, the Bitcoin Red Team has incorporated Z.ai’s $GLM 5.2, along with models from OpenAI and Anthropic. However, U.S.-developed models come with significant restrictions, often hindering developers’ efforts in security research. “Red team hindered by OpenAI cyber issues again,” Calle tweeted earlier this week. “We don’t like seeking permission. Switching to Kimi K3.”

Red team 🟥 hindered by OpenAI cyber issues again.

We don’t like seeking permission. Switching to Kimi K3. pic.twitter.com/wCEV2HYpLo

— calle 🟥 (@callebtc) August 11, 2026

Calle emphasized that despite challenges, the team is making headway, albeit slowly.

In August, the team reported documenting 4,962 findings across 390 different projects, which included 85 classified as critical and 635 identified as high severity. Calle mentioned that developers have verified “a substantial number of real critical and high vulnerabilities,” although the group has not disclosed the specific projects or technical details.

“The rate of response varies widely among projects and is indicative of each project’s health,” they commented. “I advise acting quickly these days.”

The review process for Lightning software, which facilitates quicker and more cost-effective Bitcoin transactions, proved particularly challenging due to its complexity, with Calle labeling it “more flawed than average.”

“Projects that initiated AI audits months ago are in a significantly better position than those that did not,” Calle noted. “It’s essential for projects to establish their own AI audit frameworks looking ahead.”

Calle further cautioned against depending on projects that are not actively maintained and pointed out that AI advancements have increased the pressure on developers to maintain the security of their software.

The Bitcoin Red Team is not acting independently; last month, Hugging Face utilized China’s $GLM 5.2 to examine a breach after OpenAI models compromised its systems, while U.S. commercial models refused to analyze the resulting attack logs.

Despite stating that Bitcoin is “burning,” Calle argued that the auditing process is reinforcing the software’s integrity.

“Bitcoin is an obvious initial target, but other sectors will soon follow,” Calle remarked. “Sometimes, older systems need to burn away for new innovations to flourish on fertile ground.”

Share.