
Developers form volunteer group to proactively scan the Bitcoin ecosystem for vulnerabilities as AI lowers the barrier to entry for malicious hackers.
AI-generated summary
The Bitcoin Red Team was formed to address security threats in the Bitcoin ecosystem following the Coldcard wallet hack. The group focuses on software built around Bitcoin rather than the protocol itself.
AI is putting powerful hacking capabilities in the hands of people with little cybersecurity expertise, forcing crypto developers into a race to find vulnerabilities before attackers exploit them.
One group taking on that challenge is the Bitcoin Red Team, whose pseudonymous member and Bitcoin software developer Calle said formed as an emergency effort to find AI-assisted security threats across the Bitcoin ecosystem.
"At this point, it is a question about time,” Calle, who helps maintain the open-source protocol Cashu, told Decrypt. “The reason why the Bitcoin Red Team exists right now is because we need to get ahead of the attackers as fast as possible.”
The Bitcoin Red Team consists of about 20 to 25 volunteers, according to Calle, many of whom prefer to remain pseudonymous, such as Bitcoin privacy protocol developers Stu, Talip, and fellow Cashu dev thesimplekid. Others in the group include Bitcoin developers Ben Carmen, Daniela Brozzoni, and James O'Beirne, and Vinteum Bitcoin R&D Center board member Bruno Garcia.
Calle said the Bitcoin Red Team began taking shape after CEO of Bitcoin Insurance firm AnchorWatch Rob Hamilton started examining Bitcoin projects following the Coldcard air-gapped wallet hack.
While Calle stressed that the group has found no issues in the Bitcoin protocol itself, the concern he said instead lies with applications, wallets, services, and other software built around Bitcoin.
"Although Bitcoin itself is secure, the software that we're using to transact with Bitcoin may not be, and that is what most people interface with anyway," Calle said.
The Coldcard exploit, attacks on other Bitcoin services, and the release of more powerful Chinese AI models pushed Calle and other security researchers to join the effort and move quickly.
"I think the arrival of Kimi K3 has also caused a lot of chaos in the cybersecurity realm because it gave attackers as well as defenders unprecedented power," he said.
As Calle explained, the Red Team receives requests from Bitcoin projects seeking security scans but also searches for vulnerabilities on its own.
"We get a bunch of inbound requests from projects that want to be scanned, but we act proactively, and we've covered almost the entire significant open-source ecosystem by our own sweeps already," Calle said. "So even if you come and ask us to scan your project, we've probably scanned it already."
The group shares its findings with affected developers and uses their feedback to improve its vulnerability classifications and severity ratings.
Chinese models fill the gap
Chinese AI models are used far more than their U.S. counterparts for the group's security work because guardrails on American models can block cybersecurity research, Calle said.
“It's not even close," he said.
In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation, while the Trump administration warned in April that Chinese entities were conducting similar campaigns on an “industrial scale.”
While Calle said U.S. frontier models remain arguably more capable overall, their restrictions can limit their usefulness for security-sensitive work.
"Although U.S.-based frontier models are still arguably more intelligent than any other models out there in the world, they all come with heavy guardrailing, which limits their use, especially in the cybersecurity realm," he said.
Calle encountered those restrictions before joining the Red Team. He said U.S. models sometimes refused to help find vulnerabilities and, in some cases, would not assist with fixing vulnerabilities that developers had already identified, leading him to switch to Chinese AI models.
'Bitcoin is burning'
Earlier this month, Calle described the growing security threat facing Bitcoin software as "Bitcoin is burning," referring to the wider ecosystem of wallets, exchanges, Lightning implementations and other software built around it.
Calle believes attackers are already using AI to find and exploit vulnerabilities, but avoids discussing their methods in detail out of concern that doing so could give malicious hackers ideas.
He also warned that AI is eroding the information advantage that once kept some software vulnerabilities out of reach of less-skilled attackers.
"I think that there are no secrets anymore in software," Calle said. "There is no information asymmetry that was previously being used to kind of create security theater or security through obscurity. Those times are over."
AI has also lowered the technical barrier to exploiting vulnerable software, he said.
"Simple exploits can now be completed end to end by someone who doesn't know how to do it without AI," Calle said. "So AI gave people a form of power that has completely changed the playing field."
Bitcoin may be confronting that shift earlier than other industries because attackers have a direct financial incentive to target cryptocurrency, Calle said.
"The first thing that, as an attacker, you would want to attack is internet money," he said. "So we are the beginning of a larger change in society or in computer systems in general, and I'm convinced that other industries will experience the same thing as we do right now later."

Hazync, a Bitcoin validation research project, reported a 27-millisecond verification time for a cryptographic receipt covering 1,789 blocks. The project aims to reduce node synchronization costs by using zkVM proofs, though full genesis-to-tip proofing remains unfinished.

Microsoft has patched a critical, remotely exploitable vulnerability in its Entra ID identity platform. Tracked as CVE-2026-69836 with a 10.0 CVSS score, the flaw allowed for unauthorized code execution, though Microsoft confirms it was not exploited in the wild.

A Pew Research Center study indicates that 10% of English-language webpages contain significant AI-generated content, rising to 35% for pages published after November 2022. The trend is most prevalent on .com domains compared to .edu or .gov sites.

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.

Ethereum's better.codes contest tracks a 52.14-bit cryptographic proof gap for the koalaIRS12 parameter profile, measuring distance between certified safety and unsafe bounds via soundness and attack tracks.