The case shows how much AI has expanded the speed and scope of open-source security checks. [Photo: Reve AI]

Security research is under way to identify vulnerabilities in Bitcoin’s open-source ecosystem using Chinese artificial intelligence models. The approach combines AI and human review to examine Bitcoin-related open-source projects, from wallets and Lightning applications to software libraries.

Decrypt, a blockchain media outlet, reported on Aug. 13 that the Bitcoin Red Team, led by a pseudonymous developer called Calle, is using Moonshot AI’s Kimi K3 as a key tool to probe for vulnerabilities in Bitcoin open-source code. It is also using GLM 5.2 from Chinese developer Z.ai, as well as AI models from OpenAI and Anthropic.

Kimi K3 is designed to analyse large codebases and carry out long software tasks with limited supervision. The red team conducts audits by having humans verify vulnerabilities after AI flags them. Calle described the situation by saying, "Decades of accumulated open-source code and the 2-week-old Kimi K3 are colliding head-on," adding, "Everything is broken, and Bitcoin is burning."

The checks have found vulnerabilities on a substantial scale. Calle said the red team had reviewed a total of 4,962 findings across 390 projects as of August. Of these, 85 were classified as critical and 635 as high severity. It is not disclosing affected projects or detailed vulnerability information to give developers time to respond.

When a vulnerability is confirmed, the red team first privately shares details with the relevant project developers and gives them time to fix it. It then discloses the details after the issue is resolved.

Response times differed by project. Calle explained that how quickly a development team responds to vulnerabilities can be an indicator of a project’s health. Lightning-related software, which processes Bitcoin payments quickly and cheaply, was structurally complex and difficult to audit, and was reported to have more issues than typical projects.

An interesting point was that tool choice was influenced more by restrictions on the use of tools for security research than by the AI model’s country of origin. Calle said the research was blocked due to OpenAI’s usage restrictions related to cyber security, and he also expressed an intention to use Kimi K3. It means Chinese models are being used as an alternative as the scope of work allowed for security researchers using AI narrows.

The red team argued that each open-source project should build its own AI security audit system. Calle said the gap is widening between projects that have already started AI audits and those that have not, and stressed that each project needs to establish its own AI audit pipeline.

AI-based open-source security audits are not expected to be limited to Bitcoin. A case was previously reported in which Hugging Face used China’s GLM 5.2 after a U.S. commercial AI model refused to analyse attack logs during an investigation into a security breach.

Calle forecast that Bitcoin would be only the first major target of AI-based security audits, with other open-source ecosystems to follow. As AI becomes able to rapidly analyse code accumulated over decades, the possibility is also growing that a new competitive landscape in open-source security will form between U.S. and Chinese AI models.

Keyword

#Bitcoin #Kimi K3 #Moonshot AI #GLM 5.2 #OpenAI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.