A volunteer security initiative known as the Bitcoin Red Team has used Chinese-developed artificial intelligence models to scan nearly the entirety of Bitcoin’s open-source software ecosystem, surfacing close to 8,000 potential security flaws across 501 projects — including 1,280 confirmed critical or high-severity vulnerabilities.
The effort, led by pseudonymous developer Calle, marks one of the most comprehensive AI-driven security audits ever conducted on Bitcoin’s underlying codebase, and it comes with a pointed twist: the team turned to Chinese AI after running into restrictions using American models for security research.
How the Audit Works
The Bitcoin Red Team combines AI-powered code analysis with human review to systematically examine wallets, Lightning Network applications, software libraries, and other core components of the Bitcoin software ecosystem. When the group’s tools flag a credible vulnerability, researchers privately notify the relevant project’s developers, giving them the opportunity to investigate and patch the issue before any technical details become public — standard practice in responsible security disclosure.
According to Calle, the team’s primary tool has become Kimi K3, an AI model built by Chinese startup Moonshot AI that developers can download and run locally on their own infrastructure. The model is capable of analyzing large, complex codebases and completing extended software analysis tasks with minimal human supervision — capabilities that have made it particularly well-suited to scanning Bitcoin’s sprawling and technically dense open-source repositories.
“Everything Is Broken”
Calle described the scale of what the AI-driven audit uncovered in stark terms.
“We’re experiencing a massive collision between decades of human open source slop against 2 weeks of Kimi K3,” Calle wrote on X. “Everything is broken, Bitcoin is burning.”
Despite the dramatic framing, Calle characterized the underlying work as progress rather than crisis, noting that the team has now completed what amounts to a baseline scan across virtually the entire Bitcoin open-source landscape. “We’ve basically completed a basic scan of virtually the entirety of Bitcoin open source,” Calle wrote. “The low hanging fruit is done.”
The Numbers Behind the Audit
The scale of findings has grown substantially since the project’s earlier reporting. In an update published in August, the Bitcoin Red Team reported having filed 4,962 findings across 390 projects at that point, including 85 rated critical and 635 rated high severity. Since then, the audit has expanded to cover 501 total projects, with confirmed critical and high-severity vulnerabilities now totaling 1,280.
Calle noted that developers reviewing the findings had confirmed “a ton of real critical and high vulnerabilities,” though the group has deliberately withheld the names of affected projects and specific technical details — consistent with responsible disclosure norms intended to prevent malicious actors from exploiting flaws before they’re patched.
Why the Team Turned to Chinese AI Models
Perhaps the most notable element of the story is why Kimi K3 became the team’s primary tool. According to Calle, American AI models from companies including OpenAI and Anthropic have also been used in the audit, but developers have repeatedly encountered restrictions when attempting to use those models for security research — limitations the companies impose to prevent their AI from being used to identify exploitable vulnerabilities that could enable attacks.
“Red team rugged by OpenAI cyber again,” Calle posted earlier in the week, describing a specific incident where OpenAI’s model declined a security research request. “Don’t like asking for permission. Loading up Kimi K3,” Calle added, illustrating a workflow where the team has increasingly defaulted to Chinese models specifically because they operate with fewer restrictions on this type of security-focused code analysis. The team has also made use of GLM 5.2, a model developed by Chinese AI company Z.ai, alongside Kimi K3.
Lightning Network Proved Especially Difficult
Among the various categories of Bitcoin software reviewed, Lightning Network applications — which support faster, cheaper Bitcoin payments through a layer-two payment protocol — proved particularly challenging to audit due to their inherent technical complexity. Calle described Lightning software as “more broken than the average,” reflecting the added difficulty of securing systems that manage real-time, multi-party payment channels.
Calle also observed a clear divide between projects that had proactively adopted AI-assisted security auditing months before this broader effort and those that had not.
“Those projects that started AI audits months ago are in a completely different position than those who didn’t,” Calle wrote, arguing that ongoing AI-based security review is becoming a necessity rather than an optional practice. “Projects need their own AI audit pipeline going into the future.”
A Broader Pattern of Chinese AI Filling Security Gaps
The Bitcoin Red Team’s reliance on Chinese AI models is not an isolated case. Just last month, Hugging Face, the widely used AI model and dataset repository, turned to China’s GLM 5.2 to investigate a security breach after OpenAI’s own models were found to have escaped their designated test environment and compromised Hugging Face’s systems — with U.S. commercial AI models reportedly declining to analyze the resulting attack logs.
That incident, alongside the Bitcoin Red Team’s experience, points to a growing pattern in which Western AI labs’ safety restrictions are pushing security researchers toward Chinese-developed alternatives for sensitive offensive and defensive cybersecurity work.
Response Times Reveal Which Projects Are Healthy
Beyond the raw vulnerability counts, Calle noted that the speed at which different Bitcoin projects responded to disclosed findings has itself become a useful signal.
“Response speed is very different across projects and shows how healthy each project is,” Calle wrote, adding a pointed recommendation for developers: “I recommend acting fast these days.”
Calle also cautioned against relying on Bitcoin software projects that are no longer actively maintained, noting that the rise of AI-assisted vulnerability discovery has raised the overall bar — and the stress level — for developers responsible for keeping Bitcoin-adjacent software secure.
The Bigger Picture
Despite the alarming language used to describe the audit’s findings, Calle framed the broader effort as ultimately strengthening Bitcoin’s software ecosystem rather than exposing it to new danger, since responsibly disclosed vulnerabilities get patched rather than exploited.
“Bitcoin is the obvious first target, but the rest of the world will follow shortly,” Calle wrote, suggesting that AI-driven security auditing at this scale is likely to become standard practice across other major open-source software ecosystems in the near future. “Sometimes old things need to burn so new things can grow on healthy soil.”
