The open-source Bitcoin ecosystem has just undergone a massive scan, with the results forcing many developers to review their code. The Bitcoin Red Team, a volunteer group combining artificial intelligence and human review, reported the discovery of 4,962 security vulnerabilities across 390 different projects as of August 2026. Out of these thousands of findings, 85 were classified as critical vulnerabilities, while 635 fell into the high-risk category.
The team lead, using the pseudonym Calle on the X platform, stated openly, “everything is broken, Bitcoin is on fire.” He emphasized that this situation is not the end of the world, but rather a cleanup phase that will ultimately make the Bitcoin network stronger. The main engine behind this massive scan is Kimi K3, an AI model developed by China-based Moonshot AI. Unlike typical commercial models, Kimi K3 can be downloaded and run locally on self-hosted servers. Its ability to analyze massive codebases allowed the team to complete the long task with almost no human supervision. Core developers have confirmed these findings and acknowledged the presence of real critical vulnerabilities in their systems.
A Tough Test for the Lightning Network
To date, details of which projects are affected remain closely guarded and have not been publicly disclosed to prevent exploitation. However, Calle provided a specific hint: the Lightning Network is “more broken than average.” The technical complexity of Bitcoin’s second-layer scaling solution makes it prone to accumulating issues that are difficult to detect through traditional code audits. To prevent further damage, all findings were handed over directly to the project developers via private channels to be patched before the details are released publicly.
Given the scale of the issue, Calle urged crypto project developers to stop relying on code from outdated repositories that are no longer maintained. He suggested that development teams immediately build their own self-hosted, AI-based audit systems in-house. According to him, projects that initiated AI audits months ago now exhibit much stronger resilience compared to those that have not yet started.
Why Rely on Chinese AI?
Choosing a Chinese-made AI model for this operation was not just a matter of preference, but a solution to technical limitations. Alongside Kimi K3, the Bitcoin Red Team tested the GLM 5.2 model from Z.ai (China), as well as products from OpenAI and Anthropic. In reality, commercial models built in the United States frequently refused to complete the auditing tasks. Safety filters from US manufacturers flagged vulnerability scanning requests as suspicious activity, leading Calle to complain that his team was once again held back by “OpenAI’s cyber system again.”
This deadlock has a precedent. In July 2026, the AI repository platform Hugging Face was forced to switch to China’s GLM 5.2 to investigate a system breach. The incident was triggered by an attack carried out via an OpenAI model, but strangely, other US-made commercial models refused orders to analyze the attack logs. When serious security audits require uncensored models that do not obstruct investigations, researchers now know where to look for assistance.
The defense of the crypto world is gradually demanding tools that can be fully controlled on self-hosted servers, independent of corporate technology giants’ interference. Reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




