A volunteer group calling itself the Bitcoin Red Team filed 4,962 security findings across 390 open-source Bitcoin projects in just 27.5 hours, including 85 rated critical and 635 rated high-severity. The sprint, run August 4–5, 2026, was led by pseudonymous developer Calle alongside Rob Hamilton, CEO of Bitcoin insurer AnchorWatch, and drew sixteen researchers working around the clock across time zones.

The effort was a direct response to the Coldcard breach, in which attackers exploited a flaw in the hardware wallet's random-number generator to drain funds from MK3+ devices. That incident convinced the group that Bitcoin's open-source stack needed a far more aggressive, AI-accelerated audit than any single team of human reviewers could realistically deliver.

a pile of bitcoins sitting on top of a table
Photo by Erling Løken Andersen on Unsplash

Why Chinese Models

The Red Team's tool of choice was unusual: Kimi K3 from Chinese startup Moonshot AI and GLM 5.2 from Chinese developer Z.ai, run alongside American models where permitted. Calle has said that American AI providers have restricted the kind of open-ended security research the audit requires, pushing the team toward Chinese alternatives that imposed fewer guardrails on probing for exploitable code paths.

“Everything Is Broken”

Everything is broken, Bitcoin is burning.

That was Calle's blunt summary after watching Kimi K3 collide with Bitcoin's legacy codebase. The team singled out Lightning Network software as “more broken than average” and urged any project that hasn't yet run an AI-assisted audit to do so quickly, warning developers against continuing to lean on unmaintained dependencies that no one is actively watching for new classes of bugs.

Related: Fake Hyperliquid Google Ad Drains About $550,000 From Users

An Ecosystem Under Strain

The audit itself cost more than $40,000 in AI compute, funded by OpenSats, the nonprofit that bankrolls much of Bitcoin's open-source development. The team has no public website or GitHub repository yet, though Hamilton has said the audit harness will eventually be open-sourced so Bitcoin companies can point it at their own closed-source code. In the meantime, maintainers are struggling to keep pace: developers have described the current backlog as “extremely bad” and apologized publicly for the chaos, while the team is still working out how to filter genuine vulnerabilities from lower-quality AI-generated noise — a challenge a separate Ethereum Foundation study also flagged, concluding that human validation remains necessary even when AI agents surface real bugs.

AI's growing footprint in Bitcoin isn't limited to security research, either. On the industrial side, public Bitcoin miners have been cutting hashrate as they redirect infrastructure toward AI compute, a reminder of how thoroughly the two technologies are becoming intertwined across the industry.

The stakes go beyond one bad quarter of bug reports. The Bitcoin Policy Institute has warned that without reliable access to leading AI models, Bitcoin's mostly volunteer developer base risks falling behind attackers who face no such restrictions, and has said it has received reports that sophisticated actors — possibly including foreign adversaries — are already using advanced AI to sustain pressure on the ecosystem's open-source maintainers.