A team of more than 20 anonymous members is fighting against AI-assisted attacks, relying on Chinese AI models to fill the gap left by the "safeguards" in American models.
Written by: Jason Nelson
Translated by: Saoirse, Foresight News
Artificial intelligence has handed powerful hacking tools to a large number of people lacking cybersecurity expertise. Cryptocurrency developers are forced to enter a race: they must find system vulnerabilities before attackers do.
The Bitcoin Red Team is the group taking on this challenge. Calle, an anonymous member and Bitcoin software developer, said that the formation of this team is a response to the urgent security threats within the Bitcoin ecosystem spawned by AI assistance.
"Right now, it's only a matter of time," Calle, who participates in maintaining the open-source protocol Cashu, told Decrypt. "The reason the Bitcoin Red Team was established is so we can stay ahead of the attackers as much as possible."
According to Calle, the Bitcoin Red Team consists of 20-25 volunteers, many of whom choose to remain anonymous, such as Bitcoin privacy protocol developers Stu and Talip, as well as the developer thesimplekid, who also maintains Cashu. Other team members include Bitcoin developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Bruno Garcia, a board member of the Vinteum Bitcoin Research Center.

Calle stated that Rob Hamilton, the CEO of the Bitcoin insurance company AnchorWatch, began assessing various Bitcoin projects in response to the hacking incident involving Coldcard offline hardware wallets, which contributed to the gradual formation of the Bitcoin Red Team.
Calle emphasized that the team has not found issues within the Bitcoin base protocol itself, but risks are concentrated in wallets, various applications, services, and other third-party software built on Bitcoin.
"The Bitcoin base itself is secure, but the various software that ordinary people use to perform Bitcoin transactions may not be secure, and the vast majority of users are in contact with just these upper-layer software," Calle said.
The Coldcard wallet was hacked, multiple Bitcoin-related services faced attacks, and with stronger Chinese AI models emerging, Calle and other security researchers were motivated to engage in this work and accelerate the assessment process.
"I believe the emergence of Kimi K3 has also brought a lot of turmoil to the cybersecurity field, as it gives both attackers and defenders unprecedented capabilities," he stated.
Calle explained that the red team accepts security scanning requests from Bitcoin projects while also proactively searching for vulnerabilities.
"Many projects will reach out to us, hoping we can conduct scans, but we also take the initiative. Through our own assessments, we have almost covered all the significant open-source projects within the ecosystem. In other words, even if a certain project only comes to us for scanning, we might have already scanned it," he said.
The team will feed back discovered vulnerabilities to the corresponding project developers and optimize vulnerability classification standards and danger level assessment rules based on the developers' feedback.
Chinese AI Models Filling Tool Gaps
Calle noted that during the team’s security-related work, the frequency of using Chinese AI models far exceeds that of American counterparts due to the built-in security protections in American models that block tasks related to cybersecurity research.
"The difference between the two is very evident," he said.
In February this year, Anthropic accused Chinese AI laboratories DeepSeek, Moonshot AI, and MiniMax of using about 24,000 fake accounts to steal more than 16 million Claude conversation data through model distillation technology. The Trump administration issued a warning in April that Chinese-related entities are conducting similar stealing activities on an "industrial scale."
Calle believes that despite the leading comprehensive capabilities of American frontier large models, strict content restrictions have diminished their practicality in security-related work.
"It is undeniable that the top American large models' overall intelligence level is still leading globally, but they all have set up heavy protective restrictions, which limit the use of the models, especially evident in the field of cybersecurity."
Before joining the red team, Calle personally experienced such restrictions. He stated that American AI models sometimes refuse to assist in finding vulnerabilities; even when faced with confirmed vulnerabilities by developers, the models are unwilling to provide help with fixes, prompting him to turn to Chinese artificial intelligence models.
"Bitcoin is Burning"
Earlier this month, Calle described Bitcoin software as facing increasingly severe security threats, coining the phrase "Bitcoin is burning," referring to wallets, exchanges, Lightning Network implementations, and all associated software ecosystems built on Bitcoin.
Calle believes attackers are already using artificial intelligence to find and exploit vulnerabilities. However, to avoid providing malicious hackers with attack ideas, he refused to elaborate on the specific methods of the attackers.
He also warned that past software vulnerabilities were inaccessible to technically insufficient attackers due to information barriers; however, artificial intelligence is dissolving this information barrier.
"There are no secrets left in the software realm. The security camouflage based on information differentials and the ambiguous security achieved through undisclosed details are no longer viable; that era is over," Calle stated.
Artificial intelligence has also lowered the technical threshold for exploiting vulnerabilities.
"Now, someone without relevant technical know-how can leverage AI to carry out simple vulnerability exploitation from start to finish. AI grants ordinary individuals this ability, fundamentally rewriting the dynamics of offense and defense," he said.
Calle believes that cryptocurrency can directly bring economic benefits, and attackers have strong monetary motives, so Bitcoin will experience this change earlier than other industries.
"The primary targets for attackers are internet digital currencies. We are at the beginning of a significant transformation in the entire computer industry, and I am confident that other industries will also encounter similar security issues that we are currently facing."
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。