Key Highlights
- Security researchers conducted an extensive review of 501 Bitcoin open-source projects, identifying 7,958 potential security issues over 108 hours
- Among these discoveries, 1,280 were rated as high or critical in terms of severity
- Moonshot AI’s Kimi K3, a Chinese artificial intelligence model, served as the core technology for this comprehensive audit
- BTCPay Server has already addressed a critical security flaw identified by the team, which included a two-factor authentication vulnerability
- Approximately 24.7% of the identified issues included reproducible evidence at the initial reporting stage, highlighting the continued necessity for human oversight
In a sweeping security initiative, Bitcoin Red Team has concluded an extensive AI-powered examination of the Bitcoin open-source landscape, documenting 7,958 potential security weaknesses across 501 different projects following 108 hours of intensive analysis.
The research collective, which merges artificial intelligence capabilities with human expertise, deployed Moonshot AI’s Kimi K3 Chinese AI model as their principal analytical instrument. The ability to operate Kimi K3 locally enables researchers to circumvent limitations they report encountering with U.S.-based AI platforms such as OpenAI and Anthropic when conducting security investigations.
According to Calle, the pseudonymous chief developer, the team has now finished an initial assessment of virtually the complete Bitcoin open-source landscape, with the most readily discoverable security weaknesses already identified and catalogued.
“We’re experiencing a massive collision between decades of human open source slop against two weeks of Kimi K3,” Calle wrote on X. “Everything is broken, Bitcoin is burning.”
Many Findings Require Further Validation
The total figure of 7,958 doesn’t represent 7,958 verified, exploitable security flaws. Among these discoveries, 1,280 received classifications of high or critical severity. Just 24.7% underwent dynamic reproduction testing, and 29.4% had been communicated to upstream project administrators at the 108-hour checkpoint.
Human validation remains an essential component of the workflow. AI-supported security audits frequently generate false alarms and redundant reports, with severity classifications subject to revision following manual examination.
A previous examination identified 4,962 possible security concerns across 390 Bitcoin projects, with 720 initially categorized as high or critical. The current figures indicate the scope broadened following that initial assessment.
BTCPay Server Addresses Critical Security Flaw
The initiative has already generated tangible security improvements. BTCPay Server acknowledged Red Team security researchers Bruno Garcia and Ben Carman for disclosing a critical security vulnerability that was under active exploitation. The version 2.4.2 update resolved a two-factor authentication circumvention issue impacting Greenfield Basic Authentication.
BTCPay subsequently verified that malicious actors had acquired administrative credentials from compromised installations and leveraged them to gain unauthorized access to linked Lightning wallets. The development team indicated they were reviewing additional vulnerability reports submitted by the Red Team and other security researchers.
On August 14, BTCPay issued another security-oriented release candidate targeting additional vulnerabilities. Community members supporting BTCPay also funded a recovery bounty and committed 0.21 BTC to the Bitcoin Red Team initiative.
Increased Scrutiny for Project Maintainers
Calle emphasized that artificial intelligence has reduced the resource requirements for discovering security weaknesses, and that projects lacking active maintenance should now face heightened scrutiny. He suggested that response speed to security disclosures serves as a valuable metric for assessing project vitality.
OpenSats has established an expedited red-teaming grant pathway to help compensate researchers for AI-related expenses. Over 40 Bitcoin and cryptocurrency-focused organizations have additionally requested that prominent AI labs provide authenticated open-source security professionals with access to advanced models.
Calle observed that Lightning Network software presented particular challenges during evaluation due to its intricate design, describing it as “more broken than the average.” He indicated that projects initiating AI-assisted security reviews months earlier now enjoy significantly stronger security positions compared to those yet to begin.
The essential message for Bitcoin users is that this comprehensive audit encompasses wallets, Lightning Network infrastructure, payment processing software, and development librariesānot Bitcoin’s fundamental consensus mechanism.





