Bitcoin Red Team Finds 7,958 Potential Security Issues Using Kimi K3

Share:
An AI-assisted Bitcoin Red Team audit scanned 501 Bitcoin open-source projects in 108 hours and logged 7,958 potential security findings, including 1,280 high or critical issues, with 24.7% dynamically reproduced and 29.4% reported upstream. The work produced real fixes—BTCPay Server 2.4.2 on Aug 7 patched a critical TOTP bypass and OpenSats updated with no lost funds—while Kimi K3 scored 32% on ExploitBench but achieved zero arbitrary code execution on 41 samples, prompting a Red Team Fund and a 40+ organization coalition and highlighting rising crypto security risks in wallets, Lightning and payment stacks and the need for faster patch cycles and adoption of verified fixes.
Bitcoin Red Team expanded its AI-assisted audit to 501 Bitcoin-related open-source projects, and logged 7,958 potential security findings after 108 hours of work.
The scale is striking, but the headline number needs context. Of the 7,958 findings, 1,280 were classified as high or critical, while only 24.7% were dynamically reproduced and 29.4% reported upstream at the latest tally. That means the dataset is better viewed as a large security triage queue than as proof of thousands of exploitable Bitcoin vulnerabilities.
The campaign nevertheless produced real-world fixes. BTCPay Server’s Aug. 7 release of version 2.4.2 warned of a critical vulnerability that was being actively exploited and credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting it. The update fixed a TOTP two-factor authentication bypass through Greenfield Basic Authentication and disabled Basic Authentication by default shortly after account creation.
The operational impact was big enough that OpenSats disclosed it had been running the affected BTCPay Server and LND stack. The nonprofit said it updated quickly, lost no donated funds and temporarily disabled Lightning donations as a precaution.
Kimi K3 turns code review into a scaling problemThe audit also sheds some light on why AI-assisted security research is changing the economics of vulnerability discovery. Calle, a pseudonymous developer involved in Bitcoin Red Team, said the group used Moonshot AI’s Kimi K3 to work through a large portion of the Bitcoin open-source ecosystem in roughly two weeks.
Independent testing suggests Kimi K3 is capable but not infallible. A joint assessment by the UK AI Security Institute and U. CAISI gave Kimi K3 a 32% score on ExploitBench, ahead of GLM-5.2’s 24%. Yet it achieved arbitrary code execution on zero of 41 samples, compared with an average of 20 successful samples for the most cyber-capable models tested.
(Source: AISI)
That gap matters. AI can dramatically increase the number of suspicious code paths researchers examine, but human verification still determines whether a report is exploitable, duplicated, incorrectly scored or harmless.
Bitcoin security enters a faster patch cycleThe bigger story may therefore be less about 7,958 individual findings and more about the speed mismatch AI creates between discovery and remediation.
OpenSats already launched a dedicated Red Team Fund that can reimburse researchers for LLM token costs. A coalition of more than 40 digital-asset organizations also called for vetted open-source defenders to receive controlled access to frontier AI models.
For users, this is not evidence that Bitcoin’s consensus protocol is broken. The more immediate risk lies in the surrounding software stack—wallets, Lightning infrastructure, payment servers and older libraries—where a single overlooked authentication or key-management flaw can translate directly into lost funds.
AI is making those weaknesses cheaper to find. The next security advantage may belong to projects that can verify, patch and ship fixes just as quickly.
Read More





