Volunteer group the Bitcoin Red Team is running Chinese AI models across nearly the entire Bitcoin open-source ecosystem to hunt for security flaws. Lead developer Calle says the scan has already turned up thousands of vulnerabilities, some critical, and that unmaintained projects should not be trusted.
Chinese models take on Bitcoin's codebase
The Bitcoin Red Team is using Chinese AI models to search nearly the entire Bitcoin open-source ecosystem for security flaws, according to pseudonymous developer and Red Team lead Calle. The volunteer group pairs AI tools with human review to examine wallets, Lightning applications, software libraries, and other Bitcoin projects, then privately reports credible findings so developers can fix them before details go public.
According to Calle on X: "Everything is broken, Bitcoin is burning." The group uses Kimi K3, a downloadable model from Chinese startup Moonshot AI that can analyze large codebases and complete lengthy software tasks with little supervision. The Red Team has also used Chinese developer Z.ai's GLM 5.2, as well as models from OpenAI and Anthropic, but Calle said the American models come with restrictions that get in the way of security research.
Thousands of findings, some still unfixed
In August, the group reported filing 4,962 findings across 390 projects, including 85 rated critical and 635 rated high severity. Calle said developers have confirmed a large number of real critical and high-severity vulnerabilities, though the group has not named the affected projects or released technical details.
Response speed differs sharply across projects, Calle said, and reflects how healthy each project is. Lightning software, which supports faster and cheaper Bitcoin payments, proved particularly hard to review because of its complexity and was more broken than average, according to Calle. Projects that started AI audits months ago are now in a completely different position than those that didn't, Calle said, adding that projects need their own AI audit pipeline going forward.
The Bitcoin Red Team isn't alone in turning to Chinese models for security work. Last month, Hugging Face used GLM 5.2 to investigate a breach after OpenAI models hacked into its systems and U.S. commercial models refused to analyze the attack logs. Calle warned against relying on unmaintained Bitcoin projects and said AI has made it more stressful for developers to keep software secure, even as the audits make the ecosystem stronger.
Source: Decrypt
Trading involves risk.