Key Highlights
- Security researchers analyzed 501 Bitcoin open-source projects over 108 hours, identifying 7,958 potential security concerns
- 1,280 issues were rated as high or critical severity levels
- Moonshot AI’s Chinese-developed Kimi K3 model served as the primary analysis tool
- BTCPay Server has already deployed fixes for a critical flaw, including a two-factor authentication exploit
- Just 24.7% of identified issues included reproducible evidence at initial reporting, highlighting the continued need for human verification
The Bitcoin Red Team has wrapped up an extensive AI-driven security assessment covering nearly the complete Bitcoin open-source landscape, identifying 7,958 potential vulnerabilities across 501 distinct projects during a 108-hour examination period.
This security collective, which merges artificial intelligence capabilities with human expertise, leveraged Moonshot AI’s Kimi K3 model from China as their principal analytical instrument. The ability to operate Kimi K3 locally enables researchers to bypass limitations they report experiencing with U.S.-based AI platforms such as OpenAI and Anthropic when conducting security investigations.
According to Calle, the pseudonymous project leader, the team has successfully conducted an initial assessment of virtually the complete Bitcoin open-source infrastructure, with the most easily identifiable security weaknesses now catalogued.
“We’re experiencing a massive collision between decades of human open source slop against two weeks of Kimi K3,” Calle wrote on X. “Everything is broken, Bitcoin is burning.”
Many Findings Require Further Validation
The figure of 7,958 findings doesn’t represent 7,958 verified, exploitable security flaws. Among these discoveries, 1,280 received high or critical classifications. At the 108-hour checkpoint, only 24.7% had undergone dynamic reproduction testing, while 29.4% had been forwarded to upstream project maintainers.
Human oversight remains essential throughout this evaluation process. AI-driven security assessments frequently generate false positives and redundant reports, with severity classifications often requiring adjustment following manual analysis.
A previous scanning effort identified 4,962 potential vulnerabilities spanning 390 Bitcoin projects, with 720 initially marked as high or critical. The current figures demonstrate significant expansion beyond that initial assessment.
BTCPay Server Deploys Critical Security Fix
This security initiative has already generated tangible results. BTCPay Server acknowledged Red Team researchers Bruno Garcia and Ben Carman for discovering a critical vulnerability under active exploitation. The 2.4.2 update resolved a two-factor authentication bypass impacting Greenfield Basic Authentication.
BTCPay subsequently revealed that malicious actors had extracted administrator credentials from compromised installations, utilizing them to infiltrate connected Lightning wallets. The development team indicated they’re evaluating additional vulnerability reports submitted by the Red Team and independent security researchers.
On August 14, BTCPay issued an additional security-oriented release candidate addressing supplementary vulnerabilities. Community supporters also contributed to a recovery bounty initiative and committed 0.21 BTC to the Bitcoin Red Team’s research fund.
Increased Scrutiny for Project Maintainers
Calle contends that artificial intelligence has dramatically reduced the expense of vulnerability discovery, suggesting that projects lacking active maintenance warrant heightened skepticism. Response velocity to security disclosures, he argues, serves as a reliable measure of project vitality.
OpenSats has established an expedited red-teaming grant pathway to help compensate researchers for AI-related expenses. Over 40 Bitcoin and cryptocurrency organizations have additionally petitioned prominent AI labs to provide verified open-source security researchers with access to advanced models.
Calle observed that Lightning Network software proved exceptionally challenging to evaluate given its technical complexity, describing it as “more broken than the average.” Projects that initiated AI-assisted security reviews months earlier, he emphasized, maintain substantially stronger security postures than those that haven’t.
The critical distinction for Bitcoin users is that this assessment encompasses wallets, Lightning infrastructure, payment processing software and supporting librariesānot Bitcoin’s fundamental consensus protocol itself.


