Author: Claude, Deep Tide TechFlow
Deep Tide Introduction: A volunteer group called the "Bitcoin Red Team" used Kimi K3 from the far side of the moon to scan 501 open-source Bitcoin projects in two weeks, recording 7958 findings, of which 1280 were rated as high risk or severe.
The reason for this being done by a Chinese model is that OpenAI and Anthropic refused these defensive measures on grounds of safety. If your coins are stored in some wallet or node software that hasn't been updated for years, this article is worth reading to the end.
On August 13, Calle, a member of the Bitcoin Red Team and founder of the Cashu protocol, summarized the phased conclusions of this operation on X, with his tweet receiving nearly 260,000 views. His original words were very straightforward: "Decades of open-source code collided with two weeks of Kimi K3, resulting in everything being broken; Bitcoin is burning."

Everything began with a wallet vulnerability that disappeared with 100 million dollars
On July 30, the hardware wallet Coldcard was exposed for a firmware flaw: the device reverted to a predictable software process when generating mnemonic phrases, and the security chip only provided 32 bits of entropy, leaving an effective key space of about 4.3 billion possibilities. Attackers picked up on this and drained user wallets in multiple waves, confirming losses of over 100 million dollars, with total suspected losses approaching 130 million dollars. Bitcoin Magazine exceptionally issued an emergency notice urging to "immediately transfer funds."
This disaster directly gave birth to the Bitcoin Red Team. Calle and Rob Hamilton, CEO of the custody insurance company AnchorWatch, led the effort, with dozens of contributors involved, and the nonprofit organization OpenSats reimbursed most of the computational expenses, conducting an AI audit across nearly the entire Bitcoin open-source ecosystem.
501 projects scanned in two weeks, but findings do not equal vulnerabilities
By August 8, the team had completed scanning 501 projects in over a hundred hours, recording 7958 findings, with 1280 rated as high risk or severe. These numbers need to be unpacked: at the 108th hour mark, only 24.7% of the findings were dynamically reproduced, and 29.4% were reported to the project teams; AI audits carry false positives and duplicates, and manual verification is still ongoing.
But the "inflation theory" cannot stop the hardest case. The official release record of the payment software BTCPay Server shows that a serious vulnerability reported by Red Team members Bruno Garcia and Ben Carman (two-factor authentication bypass) had already been exploited before it was patched, allowing attackers to obtain administrative credentials for the node and thus control the associated Lightning Network wallet. BTCPay quickly released two security versions, and the community set up a recovery reward for victims, while the foundation allocated another 0.21 Bitcoin to inject into the Red Team fund. The maintainers voted their trust in these findings through action.
American models apologize, Chinese models look for vulnerabilities
Why is Kimi K3 the main player instead of GPT or Claude?
Because American models do not take on this job. Rob Hamilton recounted that after completing all identity verification, he used OpenAI's model to analyze a publicly disclosed codebase, and was rejected in less than 20 minutes. The comparison from Bitcoin core contributor PortlandHODL went viral in the community: for the same code, the response from the cutting-edge American model was "You are right!", while the Chinese open-source model directly identified 78 serious vulnerabilities. Hamilton's complaint was even more poignant: "Right now, I’m basically begging Xi not to let my software be hacked."
On August 10, more than 70 custodians, exchanges, mining companies, and development organizations jointly signed an open letter from the Bitcoin Policy Institute, requesting cutting-edge AI labs to grant access to trusted defenders. Galaxy Research head Alex Thorn's co-signed comment stated, "Americans should not be forced to rely on Chinese AI for their protection. The Red Team needs these models." However, it is also essential to temper the hype: a joint evaluation by the UK's AI Safety Institute and the US CAISI showed that Kimi K3 outperformed GLM-5.2 in vulnerability development testing but still lagged behind the strongest closed-source model in the US. Defenders don't choose the strongest; they choose what is usable.
One prompt makes vulnerabilities easier to exploit
Calle’s summary holds one crucial takeaway for coin holders: "In the past, finding a buffer overflow was not enough; it required skilled hackers to turn it into a usable attack; today, it only takes one prompt."
The threshold between discovery and weaponization has collapsed, which entails three real-world implications. Unmaintained old projects are default suspicious; don’t use "it's run for many years without incident" as safety justification; the response speed of projects to vulnerability reports will henceforth serve as a public metric for assessing their health, and Calle clearly suggests "actions need to be quick during this time"; he specifically pointed out that the Lightning Network is "more broken than general projects," and the associated wallets and channel balances deserve a closer look.
As for the 501 projects, the low-hanging fruit has been picked; the basic scanning of the Bitcoin open-source ecosystem has concluded. But Calle himself said, Bitcoin is just the first one to hit this wall. When a single prompt can turn long-standing vulnerabilities into weapons, all software that relies on "no one discovering anything for many years" to maintain a sense of security is queuing up for its own collision.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。