Bitcoin Red Team has expanded its AI-driven security audit to 501 open-source projects related to Bitcoin, reporting a total of 7,958 potential security issues after 108 hours of analysis.
Critical vulnerabilities identified
Although the total number of findings is significant, further context reveals that 1,280 of these vulnerabilities were deemed high or critical. Among all logged issues, 24.7% could be dynamically reproduced, while 29.4% have been reported upstream to respective developers or maintainers. Thus, the figures serve more as an indicator of pending security triage than evidence of thousands of actively exploitable vulnerabilities in the Bitcoin ecosystem.
Of the thousands of findings, only a fraction are both severe and reproducible, highlighting the priority in focusing remediation efforts where the impact is real and verified.
The campaign led to direct improvements in live software. On August 7, BTCPay Server released version 2.4.2, warning of a critical vulnerability under active exploitation and crediting Bitcoin Red Team researchers Bruno Garcia and Ben Carman for the discovery. The update fixed a bypass in time-based one-time password (TOTP) two-factor authentication via Greenfield Basic Authentication, disabling Basic Authentication by default shortly after account creation.
Operational impact
The significance of the discovery extended to OpenSats, a nonprofit supporting open-source Bitcoin development. OpenSats revealed it had been operating the affected BTCPay Server and LND stack, but confirmed that timely updates prevented any loss of donated funds. As a precaution, the organization temporarily paused Lightning Network donations.
BTCPay Server is an open-source payment processor used widely by merchants and nonprofits for accepting Bitcoin payments. LND, or Lightning Network Daemon, provides user-friendly Lightning Network capabilities atop Bitcoin.
Mini dictionary: OpenSats is a nonprofit organization that funds open-source Bitcoin-related projects. BTCPay Server is a self-hosted Bitcoin payment processor, while LND refers to a leading Lightning Network software implementation.
AI’s evolving role in security
The audit demonstrates how artificial intelligence is transforming security research. Calle, a pseudonymous member of Bitcoin Red Team, stated that the team utilized Moonshot AI’s Kimi K3 large language model to help review a vast segment of Bitcoin’s open-source landscape within two weeks.
Independent assessments showed Kimi K3 performed capably, securing a 32% score on ExploitBench, an evaluation framework for testing AI model vulnerability detection skills. This was ahead of GLM-5.2’s 24% score. Despite this, Kimi K3 failed to achieve arbitrary code execution in any of 41 tested samples, a capability that more advanced AI security models demonstrated on up to 20 samples.
| AI Model | ExploitBench Score | Arbitrary Code Execution (out of 41 samples) |
|---|---|---|
| Kimi K3 | 32% | 0 |
| GLM-5.2 | 24% | Not specified |
| Most cyber-capable models | Average not specified | 20 |
These findings suggest AI can scan broad codebases and surface suspicious cases more efficiently, but human expertise is still required to validate which vulnerabilities are real and exploitable, as opposed to false positives or duplicates.
Funding and future developments
In response to these findings, OpenSats launched a Red Team Fund to reimburse researchers for the costs of running large language models. Simultaneously, a coalition of more than 40 digital asset organizations has advocated for vetted security experts to be granted controlled access to advanced AI models in order to better defend open-source software.
For everyday users, the immediate risks are not at the level of Bitcoin’s consensus protocol, but rather in the wider software infrastructure such as wallets, Lightning nodes, payment servers, and legacy libraries. Even a minor lapse in authentication or key management can potentially result in direct financial loss.
AI is driving down the cost of finding these weaknesses, which may eventually give an edge to open-source projects that can rapidly verify, patch, and distribute fixes as quickly as threats emerge.





USDT
AAPL
