The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

Bitcoin red team: AI discovers critical vulnerabilities in Bitcoin open source

Red Bitcoin coin with alert triangle on circuit board background.
Red Bitcoin coin with alert triangle on circuit board background.

A Bitcoin security researcher shares the findings of a red team that spent two weeks using the AI tool Kimi K3 to comb through Bitcoin open source code. The results are striking: dozens of critical and severe vulnerabilities have been found and confirmed by project maintainers. At the same time, the team argues that Bitcoin actually emerges stronger from this process.

Bitcoin is available at OKX and Bybit.

In short:

  • The Bitcoin red team completed a baseline scan of nearly all Bitcoin open source projects using Kimi K3.
  • Numerous critical vulnerabilities were found and confirmed, including issues with the Lightning Network.
  • AI lowers the threshold for finding security vulnerabilities, making unmaintained projects especially vulnerable.

Critical vulnerabilities found in Bitcoin open source

Calle, a researcher on the Bitcoin red team, shares a series of conclusions on X after weeks of intensive work. In doing so, the team ran into a tension between human open source code built up over many years and what a modern AI can uncover in just two weeks. According to Calle, “everything is broken” and Bitcoin is figuratively on fire, but he simultaneously sees this as something positive: the network becomes stronger in the long run.

The situation surrounding the Lightning Network is particularly striking. Calle admits that this protocol is more complex and vulnerable than average. He also explicitly warns against using the programming language C for Bitcoin-related software. He even repeats that message twice in his post, for clarity.

AI as a standard security tool

The findings show that projects that began AI-driven security audits months ago are now in a considerably better position than projects that did not. Calle expects that every project will need its own AI audit pipeline in the future. The pressure on developers to keep software secure is increasing and has now become considerably heavier, he states.

The team considers unmaintained projects unreliable in any case. Moreover, AI makes it increasingly cheaper to find vulnerabilities, which increases the risks for poorly maintained code. According to Calle, the speed with which project maintainers respond to reported vulnerabilities says a lot about the overall health of a project. He advises everyone to act quickly.

Responsible disclosure is crucial

Calle closes his post with a clear message about ethics in security research. Anyone who does not report found vulnerabilities responsibly, or publicly flaunts them before a project has had the chance to respond, disqualifies themselves as a serious researcher. In his view, trust is the most important currency in this field, and you do not simply restore it once it is gone.

The red team indicates that the baseline scan of nearly the entire Bitcoin open source codebase is now complete. The low-hanging fruit has been picked. According to Calle, external red teaming will remain a permanent necessity in the future, because the search for vulnerabilities works best through multiple simultaneous and diverse human approaches.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Bitcoin News

More news ›