
The Bitcoin Red Team has significantly expanded its AI-assisted security review, scanning 501 Bitcoin-related open-source projects and logging 7,958 findings after 108 hours of work. According to reports from Crypto.news, the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem, with Calle, a pseudonymous Bitcoin developer, noting that much of the easier-to-find vulnerability surface has already been examined. The Kimi K3 model from Moonshot AI became the campaign's primary AI workhorse as researchers tested Bitcoin open-source software extensively. The headline numbers require important distinction, as the 7,958 findings do not represent 7,958 confirmed exploitable vulnerabilities. The team classified 1,280 findings as high or critical, while 24.7% of all findings had been dynamically reproduced and 29.4% had been reported upstream at the 108-hour mark.
More than 36 Bitcoin and crypto firms have called on leading AI laboratories to provide controlled access to advanced cybersecurity models as AI-assisted cyberattacks become more sophisticated. According to reports from Bitcoin Policy Institute, the coalition includes major digital-asset companies such as Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, Exodus, and others, alongside nonprofit developer funds including Brink, Chaincode and Btrust. The initiative was announced in an August 10 X post by Bitcoin Policy Institute, representing organizations across the digital-asset ecosystem. The coalition specifically requested early model access, computing power, secure environments, and direct communication channels with AI laboratory security teams. Bitcoin Policy Institute argued that current restrictions can leave qualified defenders relying on less capable AI tools while sophisticated attackers gain access to advanced systems.
The request follows several AI-assisted attacks and major Bitcoin security failures reported in 2026, as reported by Bitcoin Policy Institute. Recent incidents include a firmware build error affecting Coldcard hardware wallets that reportedly weakened entropy used for seed phrases, with Galaxy Research estimating confirmed thefts at 1,596 BTC and potential losses reaching 2,055 BTC. Additionally, Bitcoin Red Team found 4,962 potential issues across 390 Bitcoin-related projects during fewer than 30 hours of AI-assisted code reviews, with 720 initially classified as high or critical severity. The coalition argues that current model safeguards restrict legitimate security research while allowing criminals and state-backed groups access to increasingly capable systems. The Bitcoin Policy Institute pointed to the amount of capital dependent on such software, noting that Bitcoin alone secures more than $1 trillion in value, making serious vulnerabilities a significant risk to user savings.
BTCPay Server has released fixes after the Bitcoin Red Team and independent researchers reported critical security vulnerabilities. According to Crypto.news, Version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication, with the project confirming that attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets. BTCPay later confirmed that attackers had already exploited the vulnerability to drain Lightning nodes belonging to merchants. The project said it was processing additional reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers while strengthening its scanning and review processes. On August 14, BTCPay announced another security-focused release candidate, v2.4.3-rc4, addressing vulnerabilities reported by those groups. BTCPay supporters backed a recovery bounty after the earlier exploit and the foundation pledged 0.21 BTC to the Bitcoin Red Team fund.
The appeal complements broader security initiatives, including the Bitcoin Security Consortium established by Strategy, BlackRock, Coinbase, and six other companies with $15 million pledged over three years. According to Bitcoin Policy Institute, no leading AI laboratory had publicly announced a program responding to the coalition's specific requests at the time of writing. The Managed Intelligence Alliance represents a vendor-neutral approach to AI standards development, with Pax8 serving as the alliance's initiating member and GTIA Chief Community Officer MJ Shoer expecting hundreds of members to be actively involved within the next year. The Bitcoin Policy Institute emphasized that without dedicated access programs, defenders may lack the tools needed to keep pace with evolving threats to the infrastructure they maintain. The Bitcoin Red Team's findings demonstrate how unmaintained projects should now be treated with greater caution because AI has sharply lowered the cost of finding and testing weaknesses, with maintainers increasingly needing their own continuing AI audit pipelines rather than occasional external reviews.