TLDR
- Bitcoin Red Team scanned 501 Bitcoin open-source projects and logged 7,958 findings after 108 hours of work
- Of those findings, 1,280 were classified as high or critical severity
- Chinese AI model Kimi K3 from Moonshot AI was the primary tool used in the review
- BTCPay Server already patched a critical vulnerability reported by the Red Team, including a two-factor authentication bypass
- Only 24.7% of findings had reproducible proofs at the time of reporting, meaning human verification is still needed
Bitcoin Red Team has completed a broad AI-assisted scan of nearly the entire Bitcoin open-source ecosystem, logging 7,958 potential security issues across 501 projects after 108 hours of work.
red team 🟥 rugged by openai cyber again.
don't like asking for permission. loading up kimi k3. pic.twitter.com/wCEV2HYpLo
— calle 🟥 (@callebtc) August 11, 2026
The group, which combines AI tools with human reviewers, used Chinese AI model Kimi K3 from Moonshot AI as its main tool. Researchers can run Kimi K3 locally, which avoids the restrictions they say they encountered with American AI providers like OpenAI and Anthropic during security research.
Calle, the pseudonymous lead developer, said the team had now completed a basic scan of nearly the entire Bitcoin open-source ecosystem and that the easier-to-find vulnerabilities have already been examined.
“We’re experiencing a massive collision between decades of human open source slop against two weeks of Kimi K3,” Calle wrote on X. “Everything is broken, Bitcoin is burning.”
Not All Findings Are Confirmed Vulnerabilities
The 7,958 number does not mean 7,958 confirmed, exploitable vulnerabilities. Of those findings, 1,280 were classified as high or critical. Only 24.7% had been dynamically reproduced and 29.4% had been reported upstream to project maintainers at the 108-hour mark.
Human verification is still a key part of the process. AI-assisted audits can produce false positives and duplicate reports, and severity ratings can change after manual review.
An earlier sweep found 4,962 potential issues across 390 Bitcoin projects, with 720 then classified as high or critical. The latest tally shows the review expanded after that first wave.
BTCPay Server Patches Critical Bug
The campaign has already produced real-world fixes. BTCPay Server credited Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was actively being exploited. Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication.
BTCPay later confirmed that attackers had obtained admin credentials from affected installations and used them to access connected Lightning wallets. The project said it was processing additional reports from the Red Team and other researchers.
On August 14, BTCPay released another security-focused release candidate addressing further vulnerabilities. BTCPay supporters also backed a recovery bounty and pledged 0.21 BTC to the Bitcoin Red Team fund.
Pressure on Project Maintainers
Calle argued that AI has lowered the cost of finding weaknesses and that unmaintained projects should now be treated with greater caution. He said response time to security reports is a useful indicator of project health.
OpenSats has created a fast-tracked red-teaming grant route to help reimburse researchers for AI costs. More than 40 Bitcoin and digital-asset organizations have also asked leading AI labs to give vetted open-source defenders access to frontier models.
Calle noted that Lightning software was particularly difficult to review due to its complexity, calling it “more broken than the average.” He said projects that started AI audits months ago are in a much stronger position than those that have not.
The main takeaway for Bitcoin users is that this review covers wallets, Lightning infrastructure, payment software and libraries, not Bitcoin’s core consensus protocol.







