Bitcoin Red Team Completes First Scan of the Open-Source Ecosystem, Files 7,958 Findings
A group of 16 volunteers funded by OpenSats used Kimi K3 and other AI models to review hundreds of Bitcoin repositories. Maintainers have already validated a range of critical and high-severity issues.
On August 13, Bitcoin Red Team co-lead Calle (@callebtc) said the group had finished a first pass over almost the entire public Bitcoin open-source codebase. Writing on X, he said the effort had basically completed a basic scan of virtually the entirety of Bitcoin open source, and that the low hanging fruit was done. He summed up what the group had seen in blunt terms: "everything is broken, Bitcoin is burning."
Calle was explicit that the phrase does not describe the Bitcoin protocol itself. He was pointing at the wider software ecosystem built around Bitcoin, which includes hardware and software wallets, cryptographic libraries, Lightning implementations, payment tools, and hundreds of smaller open-source projects. The Bitcoin Red Team is a volunteer group that uses current AI models to review that code for security weaknesses before attackers can. The wider question of why AI shifted the balance between attackers and defenders this fast is the subject of a separate analysis.
What the group is reporting
By the August 13 update, the group reported 7,958 potential findings across 501 projects, of which 1,280 were rated critical or high severity. According to reporting on the update, roughly a quarter of the findings had been dynamically reproduced, and just under a third had been disclosed to the relevant maintainers.
The first widely circulated figures came about a week earlier. In an August 5 post, Calle said the team had grown to 16 globally distributed contributors working around the clock and had filed 4,962 findings across 390 projects in the first 27.5 hours, including 85 critical and 635 high-severity issues. The group is co-led by Calle, a maintainer of the Bitchat Android app, and Rob Hamilton, the chief executive of AnchorWatch, and it is funded by the open-source nonprofit OpenSats. By that point it had spent more than 40,000 dollars on AI model tokens.
The main model behind the scan is Kimi K3, an open-weights model released by the Chinese lab Moonshot AI. Calle described the situation as a massive collision between decades of human open source slop and two weeks of Kimi K3. The team has drawn on other models during the campaign as well.
A finding is not yet a confirmed bug
The 7,958 figure is not the same as 7,958 confirmed vulnerabilities. AI models produce suspected issues, and each one has to be reproduced and triaged before it counts as a real, exploitable flaw. Some suspected issues turn out to be exploitable. Others rest on false assumptions, sit on unreachable code paths, or are simply rated too high by the model.
Calle said maintainers across several projects had already validated a number of critical and high-severity problems. How many will hold up in the end is not yet clear. The group is keeping the technical details private until the affected projects ship fixes.
Calle singled out Lightning as the worst affected area. He described it as more broken than the average and particularly hard to review, which he put down to its complexity. He did not name specific implementations, citing the risk of pointing attackers at code that has not been patched.
The wider ecosystem is already reacting
Several Lightning-related services have run into AI-assisted attacks in recent days. On August 3, the non-custodial swap provider Boltz suspended its swap service indefinitely, saying that attackers now iterate faster than a team its size can find and patch. Boltz stressed that no user funds were at risk, because its swaps are secured by hashed timelock contracts, and that the losses were the company's alone. Its founders are stepping down, and an unnamed group has agreed to take over the service. On August 10, Blockstream launched a public beta of its own swap service, Blockstream Swaps.
Self-hosted payment software was hit too. On August 8, BTCPay Server shipped an emergency 2.4.2 release to close an actively exploited authentication-bypass flaw that was being used to drain connected Lightning nodes, telling operators to update or shut down. A follow-up 2.4.3 release candidate addressed further issues reported by Bitcoin Red Team researchers and collaborators.
The Coldcard exploit set the stage
The campaign took shape after the Coldcard hardware wallet exploit in late July. A weakness in the way some Coldcard firmware generated random numbers left certain wallets with far less entropy than advertised in the seed they produced, which let an attacker reconstruct private keys. The theft began on July 30 and initially drained around 1,083 bitcoin, worth close to 70 million dollars at the time. By August 10 the reported total had grown to more than 2,000 bitcoin. Coinkite, the maker of Coldcard, acknowledged that an attacker may have used AI to inspect its open-source firmware.
Industry asks AI labs for earlier access
On August 10, the Bitcoin Policy Institute published an open letter, signed by more than 40 organizations, asking leading AI developers to give vetted open-source security researchers early access to their most capable models, along with sufficient compute, secure research environments, and direct lines to the labs' security teams. Signatories include Block, Coinbase, Strategy, MARA, Galaxy, BitGo, Brink, OpenSats, Chaincode Labs, Spiral, Trezor, Unchained, Btrust, and Fedi. "The past several weeks have made the need for this abundantly clear," the institute wrote.
Calle also addressed security researchers directly. He argued that anyone who finds a flaw should report it privately and give maintainers enough time to fix it, and he described publicly boasting about unpatched findings or tagging affected projects on X as irresponsible. He also said that projects with no reachable maintainers should be treated as unsafe, and that users should stop relying on abandoned software.
Bitcoin Core itself is not implicated
None of this points to a flaw in the Bitcoin protocol or in Bitcoin Core, the reference software that runs the network. In November 2025, the security firm Quarkslab completed the first public third-party audit of Bitcoin Core, commissioned by the nonprofit Brink, and found no critical or high-severity issues in the areas it reviewed, which included peer-to-peer networking, the mempool, and parts of consensus handling. That does not prove the software is flawless, but it marks a clear line between Bitcoin Core and the hundreds of independent projects the Red Team is reviewing, which range from large, well-staffed teams to tools kept up by one or two people in their spare time.
Calle said the first broad scan is now largely finished. The work ahead, in his account, is verifying the reported issues, closing them, and eventually publishing the details once fixes are in place.
Sources
- 1.Calle (@callebtc) on X — Bitcoin Red Team first-scan update, August 13, 2026
- 2.Calle (@callebtc) on X — 4,962 findings across 390 projects, August 5, 2026
- 3.crypto.news — Bitcoin Red Team flags 7,958 issues after Kimi K3 scan
- 4.Bitcoin Magazine — Bitcoin Red Team finds 85 critical flaws across 390 repos
- 5.Decrypt — Bitcoin Is Burning: Red Team Turns to Chinese AI to Find Flaws
- 6.VentureBeat — Moonshot AI releases Kimi K3
- 7.TFTC — Boltz suspends Bitcoin swaps as AI attacks outpace patching
- 8.Boltz (@Boltzhq) on X — update on the future of Boltz
- 9.Blockstream — Announcing Blockstream Swaps
- 10.The Defiant — BTCPay Server tells operators to update or shut down over actively exploited flaw
- 11.BTCPay Server — Release 2.4.2 on GitHub
- 12.Bitcoin.com News — The Coldcard exploit explained: who lost bitcoin and who is at risk
- 13.crypto.news — Bitcoin defenders seek frontier AI access in 40-group push
- 14.Brink — An Independent Security Audit of Bitcoin Core
Not financial advice. CanoeBit publishes educational content only. Nothing here is a recommendation to buy, sell, or hold any asset.