Laptop displaying source code during a software security review

Bitcoin’s New Red Team Says AI Is Turning Wallet Software Into an Open Target

August 22, 2026 7:20 pm Comments

Bitcoin’s next security fight may not begin with a genius hacker finding one obscure bug by hand.

It may begin with an inexpensive AI model reading thousands of public code repositories faster than their maintainers can review them.

That threat has pushed a volunteer group of roughly two dozen developers and security researchers into an emergency sweep of the software surrounding Bitcoin. Their target is not Bitcoin’s consensus protocol.

It is the much larger layer of wallets, Lightning tools, libraries, payment services and other applications people actually touch.

Decrypt reported that the Bitcoin Red Team has scanned much of the ecosystem’s significant open-source software and is working privately with project maintainers to classify findings and get real vulnerabilities fixed. Team member Calle told the outlet that AI has lowered the skill and time required to carry some attacks from discovery through exploitation.

That distinction matters. The group is not saying that AI broke Bitcoin itself.

It is warning that software built around the network can contain ordinary coding mistakes—and that machines can now search for those mistakes at a scale that was recently out of reach for most attackers.

Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch and one of the organizers behind the effort, described the pace and cost of the early work in an August update:

The Red Team formed after a serious Coldcard wallet incident sharpened concern about AI-assisted vulnerability discovery. Its members include people who work on Bitcoin privacy software, hardware wallets, payment tools and core infrastructure.

Some remain pseudonymous, which is common in open-source Bitcoin development, while others are established maintainers and security researchers.

An earlier Decrypt report said the group filed 4,962 findings across 390 projects during its initial sweep, including 85 initially rated critical and 635 rated high severity. Those numbers are findings, not 720 confirmed exploitable vulnerabilities.

The team has said project developers confirmed a meaningful number of serious issues, but it has not publicly named affected repositories or released details that could help attackers before patches are ready.

That is the right disclosure posture. A dramatic count can show the scale of the review, but severity labels produced during a rapid scan still require human validation.

Duplicate reports, false positives and issues that cannot be exploited in a real deployment all have to be separated from defects that put funds at risk.

The more important signal is that maintainers are responding. The group sends credible findings to developers, incorporates their feedback and adjusts its classifications.

Calle said projects that began building AI-audit pipelines months ago are in a stronger position than teams that have not started.

The tooling gap is creating a second fight.

U.S. frontier models often place strict limits around cybersecurity prompts. Those guardrails are designed to prevent malware development and unauthorized intrusion, but they can also block legitimate researchers who are trying to reproduce, explain or patch a flaw in software they maintain.

Calle’s own post captured the frustration—and the immediate fallback to an open model:

Decrypt reported that the team has used Chinese models including Moonshot AI’s Kimi K3 and Z.ai’s GLM 5.2, alongside systems from U.S. labs. Calle’s argument is not that every Chinese model is better.

It is that a capable model researchers can actually use may be more valuable in a live security review than a stronger one that refuses the work.

That problem has moved beyond one volunteer team. CoinDesk reported that more than three dozen Bitcoin and crypto organizations asked major AI labs to create trusted-access programs for open-source defenders.

Signers included Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest and several nonprofit developer funds.

The coalition’s request is practical: early access to cyber-capable models, enough compute to run meaningful audits, secure environments for private code, eligibility for independent maintainers and a direct channel to AI-lab security teams.

The timing followed active exploits against Bitcoin software and the Red Team’s rapid audit campaign. The signers argued that small open-source maintainers should qualify for trusted programs even when they lack the corporate security departments major labs usually expect.

They also want access before new offensive capabilities spread broadly, giving defenders time to test critical financial infrastructure and coordinate fixes under controlled conditions.

Attackers do not need to qualify for a corporate partner program. They can use stolen access, open-weight models or systems with weaker restrictions.

If defenders are limited to public tools that reject legitimate analysis, the safety policy can unintentionally widen the advantage it was meant to reduce.

OpenSats is already funding the other side of the equation. The nonprofit now has a dedicated, fast-tracked application path for researchers red-teaming Bitcoin and related open-source software, including reimbursement for the large token bills these reviews can generate.

The program is listed as always open and asks applicants to provide the research context behind their work. That creates a standing route for independent researchers who can find important flaws but cannot personally absorb thousands of dollars in model usage.

OpenSats still vets applications through its nonprofit grant process, so the support is not a blank check for unrestricted hacking. It is targeted funding for defensive work on Bitcoin, Nostr and related free open-source projects.

Money alone will not solve the problem. Security findings still need careful reproduction, private disclosure, patches, release coordination and clear warnings to users who may be running vulnerable versions.

A model can accelerate the search. It cannot replace the trust and judgment required to handle a critical bug responsibly.

For Bitcoin holders, the lesson is narrower than the alarming headline.

There is no public evidence in this effort that Bitcoin’s base protocol has been compromised. The immediate risk sits in the software stack around it.

Wallets, plugins, payment servers and lightly maintained libraries can fail even when the network continues producing valid blocks exactly as designed.

Users should favor actively maintained tools, install verified security updates promptly and treat abandoned software as a real risk. Businesses running Bitcoin payment or Lightning infrastructure need an inventory of every component they depend on and a plan for emergency upgrades.

The Red Team’s work is unsettling because it shows how cheaply software can now be searched for weaknesses.

It is also encouraging for the same reason: defenders have access to the new leverage too.

The race is no longer between human attackers and human maintainers. It is between teams that build AI into their security process now and projects that wait until the machine finds them first.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.