{"slug": "bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan", "title": "Bitcoin Red Team flags 7,958 issues after Kimi K3 scan", "summary": "Bitcoin Red Team, a pseudonymous group of Bitcoin developers, has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings after 108 hours of work, with 1,280 classified as high or critical. The team's use of Moonshot AI's Kimi K3 model has been credited with accelerating the audit, and maintainers such as BTCPay Server have already patched a critical vulnerability reported by the team. The findings underscore the growing role of AI in cybersecurity, though verification by human maintainers remains essential.", "body_md": "Bitcoin Red Team has expanded its AI-assisted security review to 501 Bitcoin-related open-source projects, logging 7,958 findings in its latest detailed tally after 108 hours of work.\n\nCalle, a pseudonymous Bitcoin developer involved in the effort, said on Aug. 13 that the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem and that much of the easier-to-find vulnerability surface has already been examined.\n\nThe headline numbers require an important distinction. The 7,958 findings do not represent 7,958 confirmed exploitable vulnerabilities. The team classified 1,280 as high or critical, while 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream at the 108-hour mark. Maintainer review and human reproduction remain part of the verification process.\n\n**Kimi K3 has become a security force multiplier**\n\nCalle said two weeks of work with Moonshot AI’s Kimi K3 exposed how quickly modern models can examine years of accumulated open-source code. He described the situation as a “massive collision” between older software and frontier AI, adding “everything is broken, bitcoin is burning.” The wording is his characterization and should not be read as evidence that Bitcoin Core or every Bitcoin project is compromised.\n\nIndependent testing supports the narrower point that Kimi K3 has meaningful cybersecurity capability. A joint U.K. AI Security Institute and U.S. CAISI assessment found the model outperformed GLM-5.2 on exploit-development testing but remained behind the strongest U.S. closed models. Kimi K3 scored 32% on ExploitBench and reached arbitrary code execution on zero of 41 samples in that test.\n\nBitcoin Red Team’s earlier sweep found 4,962 potential issues across 390 Bitcoin projects, including 720 then classified as high or critical. The newer tally shows the review expanded materially after that first wave.\n\n**Maintainers are already validating and patching findings**\n\nThe campaign has moved beyond automated scanning. BTCPay Server’s official GitHub release credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was already being exploited. Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication.\n\nBTCPay later confirmed that attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets. The project said it was processing additional reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers while strengthening its scanning and review processes.\n\nOn Aug. 14, BTCPay announced another security-focused release candidate, v2.4.3-rc4, addressing vulnerabilities reported by those groups. In related coverage, BTCPay supporters backed a recovery bounty after the earlier exploit and the foundation pledged 0.21 $BTC to the Bitcoin Red Team fund.\n\nThose fixes give concrete evidence that maintainers are validating at least some serious Red Team reports. They do not validate every item in the 7,958-finding dataset. AI-assisted audits can produce false positives, duplicate reports and severity assessments that change after manual investigation, making verification central to interpreting the numbers.\n\n**Bitcoin projects face a faster security cycle**\n\nCalle argued that unmaintained projects should now be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses. He also said response time is becoming a useful indicator of project health and that maintainers will increasingly need their own continuing AI audit pipelines rather than occasional external reviews. Those are Calle’s conclusions from the campaign rather than universal security rules.\n\nThe wider ecosystem is already moving in that direction. OpenSats has created a fast-tracked red-teaming grant route focused partly on reimbursing researchers for LLM costs. More than 40 Bitcoin and digital-asset organizations have also asked leading AI laboratories to give vetted open-source defenders controlled access to frontier models.\n\nAs crypto.news reported, the industry coalition warned Bitcoin developers could fall behind attackers without access to advanced AI models. The request does not seek unrestricted access. It proposes vetted researchers, secure environments, sufficient compute and direct communication channels with AI security teams.\n\nThe next phase is likely to move more slowly than the initial sweep. Automated discovery can scale quickly, while reproduction, responsible disclosure, patch development and regression testing require more time. Projects receiving reports must determine which findings are exploitable, how urgently users need updates and when technical details can safely become public.\n\nFor Bitcoin users, the takeaway is narrower than the largest numbers suggest. The Red Team has reported a large volume of potential weaknesses across Bitcoin-related software, not evidence that Bitcoin’s base consensus protocol has failed. The immediate security concern centers on wallets, Lightning infrastructure, payment software and libraries carrying older or lightly reviewed code.", "url": "https://wpnews.pro/news/bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan", "canonical_source": "https://cryptonews.net/news/security/33294956/", "published_at": "2026-08-14 05:10:00+00:00", "updated_at": "2026-08-14 05:17:38.089034+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-tools", "ai-safety", "ai-research"], "entities": ["Bitcoin Red Team", "Calle", "Moonshot AI", "Kimi K3", "BTCPay Server", "Bruno Garcia", "Ben Carman", "OpenSats"], "alternates": {"html": "https://wpnews.pro/news/bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan", "markdown": "https://wpnews.pro/news/bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan.md", "text": "https://wpnews.pro/news/bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan.txt", "jsonld": "https://wpnews.pro/news/bitcoin-red-team-flags-7958-issues-after-kimi-k3-scan.jsonld"}}