Bitcoin Red Team Flags 7,958 Findings Across 501 Projects with Kimi K3
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Bitcoin Red Team found 7,958 potential security issues after reviewing 501 Bitcoin-related open-source projects.
- Researchers have confirmed some serious flaws, but many findings still need human testing and verification.
- AI tools are helping security researchers scan Bitcoin software faster and identify weaknesses that developers can fix.
Bitcoin Red Team expanded its AI-assisted security review to 501 Bitcoin-related open-source projects and logged 7,958 potential findings after 108 hours. Pseudonymous Bitcoin developer Calle reported the updated figures while detailing the team’s progress. Calle said researchers have completed a basic scan of almost the entire Bitcoin open-source ecosystem. He added that the team has already examined much of the easier vulnerability surface.
🚨HUGE: China's Kimi AI just scanned nearly ALL of Bitcoin's open-source code, flagging almost 8,000 flaws.
The Bitcoin Red Team has now covered 501 projects, finding 1,280 critical or high-severity issues, with maintainers validating and patching flaws.
The team leaned on Kimi… https://t.co/AZR6WOb7Ym pic.twitter.com/O5rJjC1gm3
— Coin Bureau (@coinbureau) August 13, 2026
However, the 7,958 findings do not represent 7,958 confirmed vulnerabilities. Researchers classified 1,280 findings under high or critical severity during the review. They also dynamically reproduced 24.7% of all findings within the 108-hour period. In addition, researchers sent 29.4% of the findings to affected project maintainers for technical review and possible fixes.
Calle expects deeper reviews to take longer because automated tools have already identified many easier weaknesses. The campaign covers wallets, Lightning applications, payment tools, and software libraries rather than Bitcoin’s base consensus protocol.
Bitcoin Red Team Pushes Deeper Into Software Security
Researchers use AI models to scan software before human experts reproduce credible findings and privately report them to maintainers. The Bitcoin Red Team has used Moonshot AI’s Kimi K3 and Z.ai’s GLM 5.2 during the campaign. Researchers have also worked with models from OpenAI and Anthropic. Calle said Kimi K3 helped the team examine years of accumulated open-source code within a short period.
Independent testing has also provided additional context for Kimi K3’s cybersecurity capabilities. A joint U.K. and U.S. assessment found meaningful exploit-development abilities but placed stronger closed American models ahead. Kimi K3 scored 32% on ExploitBench during the assessment. However, the model achieved arbitrary code execution on none of the 41 samples that researchers tested.
The campaign has already contributed to a confirmed security fix at BTCPay Server. Researchers Bruno Garcia and Ben Carman reported a critical vulnerability affecting Greenfield Basic Authentication. BTCPay released version 2.4.2 to close the two-factor authentication bypass. BTCPay said attackers obtained LND admin macaroon credentials from affected installations and accessed connected Lightning wallets.
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you…
— BTCPay Server (@BtcpayServer) August 7, 2026
The current campaign grew from an earlier review that followed an exploit involving Coldcard hardware wallet firmware. That incident prompted researchers to widen their examination across Bitcoin-related open-source software. The volunteer initiative then reviewed 390 projects in about 30 hours and identified 4,962 potential security issues. Researchers later expanded that work to the current review covering 501 projects.
Developers Seek Better AI Access Amid Rising Security Pressure
Aside from the Bitcoin Red Team review, more than 40 Bitcoin and crypto organizations have asked leading AI laboratories to provide controlled model access to vetted security researchers. The Bitcoin Policy Institute coordinated the industry request for researchers who protect open-source financial infrastructure. Signatories include Block, Coinbase, Strategy, MARA, BitGo, Brink, OpenSats, and BTCPay Server. They argue that access restrictions could leave defenders using weaker AI tools than sophisticated attackers.
The proposal asks AI laboratories to establish trusted-access programs rather than remove cybersecurity restrictions for every user. OpenSats also created a fast-tracked red-teaming grant route that can reimburse researchers for LLM costs. Meanwhile, SlowMist recorded 182 blockchain security incidents and about $956 million in losses during the first half of this year. The firm recorded 121 incidents and $2.373 billion in losses during the same period last year.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







