Headline: “Bitcoin Is Burning”: Volunteer Red Team Deploys Chinese AI to Hunt Security Flaws Across the Ecosystem A volunteer Bitcoin “Red Team” led by the pseudonymous developer Calle says it has used powerful Chinese AI models to scan almost the entire Bitcoin open-source ecosystem for security issues — and the results are sobering. What they’re doing - The team combines large AI models with human review to examine wallets, Lightning apps, libraries and other Bitcoin projects. - Researchers privately disclose credible vulnerabilities to maintainers so flaws can be remediated before public disclosure. Why Chinese AI? Calle says models from U.S. providers frequently impose restrictions that hamper security research. To avoid those limits, the Red Team has leaned on downloadable, locally runnable Chinese models that let researchers analyze very large codebases without asking for permission. Key models the group has used include: - Kimi K3 (Moonshot AI): a downloadable model that can tackle lengthy software tasks with little supervision. - GLM 5.2 (Z.ai): another Chinese developer model used by the team. - They’ve also used OpenAI and Anthropic models where possible, but say American models often come with practical constraints for offensive/defensive security work. “Everything is broken, Bitcoin is burning,” Calle wrote on X this week, describing “a massive collision between decades of human open source slop against 2 weeks of Kimi K3.” Scale and findings - Over August the Red Team reported 4,962 findings across 390 projects. - Of those, 85 were rated critical and 635 were rated high severity. - Calle said maintainers have confirmed “a ton of real critical and high vulnerabilities,” though the group has not publicly named affected projects or released technical write-ups. Not all projects reacted the same way. “Response speed is very different across projects and shows how healthy each project is,” Calle wrote, urging fast action. The Red Team singled out Lightning implementations as particularly challenging to audit, calling that ecosystem “more broken than the average.” Responsible disclosure and the path forward The group follows a responsible disclosure approach, privately reporting issues so fixes can be applied before details are made public. Calle argues that projects that started AI-assisted audits months ago are much better positioned than those that did not, and recommends that projects build their own AI audit pipelines going forward. Broader trend The Bitcoin Red Team is part of a wider shift in how security teams investigate software today. Last month, Hugging Face reportedly used China’s GLM 5.2 to analyze a breach after U.S. commercial models were unable or unwilling to process the attack logs, highlighting both the capability and controversy around using different model providers for incident response. A painful but strengthening process Despite the alarmist language, Calle says the audits are ultimately making Bitcoin software stronger. “Bitcoin is the obvious first target, but the rest of the world will follow shortly,” they wrote. “Sometimes old things need to burn so new things can grow on healthy soil.” Takeaway for developers and users - Projects should expect AI-driven security scans to become routine and should build AI audit pipelines into their development process. - Maintainers must act quickly on reports and avoid relying on unmaintained code. - The combination of AI efficiency and human verification can surface critical problems fast — and that speed is forcing a reckoning across open-source Bitcoin infrastructure. Read more AI-generated news on: undefined/news