Bitcoin open source ecology is entering a faster security review cycle. The Bitcoin Red Team indicated that, after approximately 108 hours of review of 501 projects, a cumulative record of 7958 problems was recorded, of which 1280 were classified as high risk or serious. However, these figures do not amount to gaps identified for use and many results still need to be further reproduced and verified by defenders and researchers.
Partial results completed and reported
From the data disclosed, approximately 24.7 per cent of the problems were validated as replicas and 29.4 per cent were submitted to the project maintainer. The code name developer Calle, who participated in the operation, stated that the team had completed the base scan of almost the entire Bitcoin open-source ecology and that the relatively easy-to-discover gaps had been examined on a wide scale.
The core tool for this round is Kimi K3 of Moonshot AI. Calle believes that the front-line model has been able to quickly check open-source codes that have accumulated over the years, exposing older software to a higher level of security scrutiny. However, it is also stressed that this does not mean that Bitcoin Core or all Bitcoin projects have been breached.
Kimi K3 was used for large-scale code audits
Independent tests have shown that Kimi K3 has some capability for cyber security tasks. A joint assessment by AI Security Institute and the United States CAISI in the United Kingdom states that the model performed better than GLM-5.2 in the gap-use development test, but still lags behind the strongest American closed-source model. Kimi K3 scored 32 per cent on Exploit Bench and did not perform any code in 41 samples.
The Bitcoin Reds had previously identified 4962 potential problems in 390 bitcoin projects, 720 of which were classified as high-risk or serious. The latest statistics show that both the scope of scanning and the number of questions have significantly expanded over the first round.
BTTCPay Server has repaired a serious loophole
This operation is no longer just an automatic scan. BTTCPay Server confirmed in a statement issued by the official GitHub that a serious loophole had been repaired on the basis of reports by Bruno Garcia, Ben Carman and independent researchers of the Bitcoin Red Corps. 2.4.2 The two-factor authentication that affected Greenfield Basic Administration was repaired, and the loophole was exploited at the time.
BTTCPay Server subsequently indicated that the attackers had obtained the LND admin macaroon voucher from the affected deployments and used it to access a connected lightning network wallet. The projecters stated that more reports from Bitcoin Red Team, Project Loupe, Magic Grants and independent researchers were still being processed, while enhancing the scanning and review process.
These repairs indicate that some of the high-risk issues in the Red Team report have been identified and addressed by the maintainers. But this does not prove that 7958 records were established. AI Auxiliary audits may still result in misstatement, duplication of reports or adjustment of risk levels following manual investigations.
Maintenance of response speed or increased attention
Calle argues that projects that have been chronically lacking in maintenance need to be viewed with greater caution as AI significantly reduces the cost of identifying and testing loopholes. The speed with which project participants respond to reports of loopholes may increasingly reflect the project ' s health. In the future, the maintainer may need to run its own AI audit process on an ongoing basis rather than relying solely on occasional external reviews.
Bitcoin ecology is also coming in this direction. OpenSats has launched the Rapid Reds Grant Channel, which partially subsidizes the LLM costs of researchers. In addition, more than 40 Bitcoin and Digital Asset Agencies have called for primary AI laboratories to provide certified open source defenders with controlled front-line model access, including a secure environment, sufficient computing power and direct communication with the AI security team.
For ordinary users, the more immediate risks continue to be concentrated on wallets, lightning network infrastructure, payment software and old code repositories, rather than on the Bitcoin bottom consensus agreement itself.
