Bitcoin open-source development enters a new phase of oversight. A volunteer red team now uses several Chinese AI models to track flaws in hundreds of projects linked to its ecosystem. The Ki
Bitcoin open-source development enters a new phase of oversight. A volunteer red team now uses several Chinese AI models to track flaws in hundreds of projects linked to its ecosystem. The Kimi K3 model, designed by the startup Moonshot AI, plays an important role in this operation. Researchers combine automated analysis capabilities and human expertise to identify risks, then discreetly warn the developers concerned before any detailed technical publication in the crypto ecosystem.
In Brief
- Kimi K3 helps the red team audit hundreds of open source projects related to Bitcoin.
- 390 projects have already been subject to in-depth security analyses.
- 4,962 anomalies were detected, including 85 critical and 635 high-risk ones.
- The team combines Chinese AI and human expertise to identify vulnerabilities.
- Lightning is among the most complex and difficult environments to audit.
A Chinese AI at the Heart of Open Source Auditing
Bitcoin’s red team reviews wallets, Lightning applications, software libraries, and other open projects. To speed up this task, it leverages Kimi K3, a model developed by Moonshot AI. Developers can download this model and run it on their systems, which facilitates its use in security research. It can also analyze large codebases and perform complex tasks with minimal supervision.
The team also uses GLM 5.2, developed by the Chinese company Z.ai, as well as models from OpenAI and Anthropic. However, Calle, a pseudonymous developer and group leader, explains that some American models impose restrictions during research.
This constraint encouraged the team to load Kimi K3 to continue its work. According to Calle, the analysis progresses slowly, but the team is now approaching a core review of the entire open source codebase of Bitcoin.
Your 1st cryptos with CoinbaseThis link uses an affiliate program.Bitcoin Faces Thousands of Detected Anomalies
In early August, the red team reported 4,962 anomalies concerning 390 projects. Among these findings, it counted 85 critical flaws and 635 high-risk issues. The researchers indicated that several developers confirmed a considerable number of significant vulnerabilities. However, they did not reveal the projects concerned nor the technical details so that teams could fix their software.
Reaction speed varies greatly depending on the projects, which also indicate their maintenance capability. The team thus recommends that developers act quickly on reported problems. The Lightning software is among the most difficult elements to examine, notably due to its complexity. Calle even considers that this environment presents more problems than the average observed in the projects studied.
This oversight also helps better target sensitive code areas and prioritize necessary fixes. These checks thus provide Bitcoin developers with more elements to organize their response to identified risks.
AI Changes Crypto Software Security
This operation mainly shows the evolution of audit methods in the Bitcoin ecosystem. Researchers now combine automation, code analysis, and human intervention to spot vulnerabilities faster.
According to Calle, projects that started AI audits several months earlier already have an advantage over those that have not engaged in this process. He estimates that “each project will gradually need to develop its own AI-assisted audit process.”
This acceleration also creates new pressure on developers. Calle especially warns against using projects no longer actively maintained. In this context, AI can multiply checks, but it also increases the pace at which teams must review and fix their software. The red team considers that “this tension can ultimately strengthen Bitcoin’s overall security, provided developers respond promptly to alerts.”
A New Method to Secure the Ecosystem
The phenomenon already goes beyond this ecosystem. Last month, Hugging Face used GLM 5.2 to investigate a flaw after OpenAI models encountered the company’s systems. American commercial models then refused to analyze some attack logs. This situation illustrates the growing interest in tools capable of directly examining complex software environments.
For teams maintaining Bitcoin, this evolution demands a reactive organization. Audits can occur before a weakness becomes public and limit user exposure. They allow prioritization of fixes according to risk level. However, automation does not replace human oversight, which is necessary to verify results and coordinate Bitcoin fixes.
In the short term, future developments will thus depend mainly on the reaction of the teams concerned. Identifying thousands of anomalies does not guarantee their immediate correction. The projects’ capacity to maintain regular audits, fix flaws, and keep active teams could become central to their security.
This evolution could therefore push more open source projects to integrate artificial intelligence into their regular checks. Developers’ responses will mainly determine if these audits sustainably accelerate vulnerability corrections.