Bitcoin’s open source development is entering a new phase of scrutiny. A volunteer red team is now using several Chinese AI models to track down flaws in hundreds of projects linked to its ecosystem. The Kimi K3 model, designed by the startup Moonshot AI, occupies an important place in this operation. Researchers combine automated analysis capabilities with human expertise to identify risks, then discreetly notify affected developers before any detailed technical release in the crypto ecosystem.

In brief
- Kimi K3 helps the red team audit hundreds of Bitcoin-related open source projects.
- 390 projects have already been subject to in-depth security analyses.
- 4,962 anomalies were detected, including 85 critical and 635 high risk.
- The team combines Chinese AI and human expertise to identify vulnerabilities.
- Lightning is among the most complex and difficult environments to audit.
Chinese AI at the heart of open source auditing
Bitcoin’s red team is reviewing wallets, Lightning apps, software libraries, and other open projects. To speed up this task, it exploits Kimi K3a model developed by Moonshot AI. Developers can download this model and run it on their own systems, making it easier to use in security research. It can also analyze large code bases and perform complex tasks with little supervision.
The team also uses GLM 5.2, developed by Chinese company Z.ai, as well as models from OpenAI and Anthropic. However, Calle, pseudonymous developer and group leader, explains that some American models impose restrictions during searches.
This constraint prompted the team to load Kimi K3 to continue their work. According to Calle, the analysis is progressing slowly, but the team is now approaching a baseline review of all of Bitcoin’s open source code.
Bitcoin facing thousands of anomalies detected
As of early August, the red team reported 4,962 anomalies across 390 projects. Among these results, it includes 85 critical flaws and 635 issues classified as high risk. Researchers said several developers had confirmed a considerable amount of significant vulnerabilities. However, they did not reveal the projects concerned or the technical details, in order to allow the teams to correct their software.
The reaction speed varies greatly depending on the projects, which also gives an indication of their maintenance capacity. The team therefore recommends that developers act quickly on reported issues. Lightning software is among the most difficult to review, particularly because of its complexity. Calle even believes that this environment presents more problems than the average observed in the projects studied.
This monitoring also makes it possible to better target sensitive areas of the code and prioritize the necessary corrections. These controls thus give Bitcoin developers more elements to organize their response to the identified risks.
AI is changing crypto software security
This operation above all shows the evolution of audit methods in the Bitcoin ecosystem. Researchers are now combining automation, code analysis and human intervention to spot vulnerabilities more quickly.
According to Calle, projects that started AI audits several months ago already have an advantage over those that have not initiated this process. He estimated as well as ” each project will gradually have to develop its own AI-assisted audit process “.
This acceleration also creates new pressure on developers. Calle particularly warns against using projects that no longer benefit from active maintenance. In this context, AI can increase checks, but it also increases the pace at which teams must review and patch their software. The red team considers that “ This tension can ultimately strengthen Bitcoin’s overall security, provided developers respond quickly to alerts “.
A new method to secure the ecosystem
The phenomenon is already beyond this ecosystem. Last month, Hugging Face used GLM 5.2 to investigate a flaw after OpenAI models have encountered company systems. American business models then refused to analyze certain attack logs. This situation illustrates the growing interest in tools that can directly examine complex software environments.
For the teams that maintain Bitcoin, this development requires a reactive organization. Audits can occur before a weakness becomes public and limit user exposure. They allow corrections to be prioritized according to their level of risk. However, automation does not replace human monitoring, which is necessary to verify results and coordinate Bitcoin fixes.
In the short term, future developments will therefore depend above all on the reaction of the teams concerned. Identifying thousands of anomalies does not guarantee their immediate correction. The ability of projects to maintain regular audits, fix vulnerabilities and maintain active teams could become a central element of their security.
This development could therefore push more open source projects to integrate artificial intelligence into their regular checks. The response of developers will above all determine whether these audits sustainably accelerate the correction of vulnerabilities.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
