Points of Focus
- Bitcoin Red Team scanned 501 projects in 108 hours, logging 7,958 findings.
- Of those, 1,280 were rated high or critical, while 24.7% had been reproduced.
- BTCPay’s exploited flaw shows why AI findings still need human verification.
Bitcoin Red Team has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings after 108 hours of work by 25 developers. Of those, 1,280 were rated high or critical, while 24.7% had been reproduced and 29.4% reported to maintainers.
The numbers still need context. The 7,958 findings are not 7,958 confirmed exploitable vulnerabilities, and severity can change once maintainers reproduce issues, assess reachability, and test fixes.
Bitcoin Red Team expands AI security scan
The latest tally extends an earlier sweep of 4,962 findings across 390 projects after 27.5 hours. “Calle,” the pseudonymous developer leading the effort, said on Aug. 13 that the team had completed a basic scan of “virtually the entirety” of Bitcoin open source and that the easier vulnerability surface was largely exhausted.
Calle also said maintainers had validated many critical and high-severity reports, while response speed varied across projects. The expanded scan now leaves maintainers with the slower work of reproducing reports, assessing their severity and shipping patches.
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.
– we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
– everything is…— calle 🟥 (@callebtc) August 13, 2026
BTCPay exploit tests Bitcoin Red Team findings
BTCPay Server provides a confirmed example. Its Aug. 7 release said version 2.4.2 fixed a critical vulnerability under active exploitation and credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reports tied to the release. BTCPay’s advisory said attackers could obtain LND “.macaroon” credentials, control affected Lightning nodes, and move funds. The project confirmed users were affected and funds were stolen.
That case validates only part of the broader data set. AI-assisted reviews can still surface false positives, duplicate reports, or severity ratings that change during manual investigation.
Kimi K3 speeds Bitcoin vulnerability discovery
Moonshot AI’s Kimi K3 has become a major tool in the campaign, but independent testing shows where its cyber capabilities still fall short. A joint UK AISI and US CAISI evaluation scored Kimi K3 at 32% on ExploitBench, above GLM-5.2’s 24%, while it achieved arbitrary code execution on 0 of 41 samples.
Verification, disclosure, and patching still require researcher and maintainer work after automated scans. OpenSats responded on Aug. 6 by creating a dedicated Red Team funding track that can reimburse large language model token costs for Bitcoin security research.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


