The results of a large-scale security screening were recently disclosed in the Bitcoin Open Source Ecology. According to the Bitcoin Red team, using the Kimi K3 model of Moonshot AI, the team combed out 7958 potential security issues within about two weeks. However, this figure is closer to a security line to be verified than the thousands of identified gaps.

1280 high-risk issues

Of these, 1280 were marked as high-risk or serious. However, as of the latest statistics, only 24.7 per cent of the problems were dynamically reproduced and 29.4 per cent were reported to upstream projects. A large number of results remain at the initial screening stage, and follow-up will require researchers to confirm whether they are actually available, duplicated or misreported.

This also indicates that AI can significantly expand the scope of the code review, but that it is still manual to verify whether or not this ultimately constitutes a loophole. For the security team, the model is more a tool to expand the scope of the screening than a substitute for the end point of the audit findings.

BTTCPay Server repaired the loophole

The round has led to physical rehabilitation. In its release of version 2.4.2 on 7 August, BTTCPay Server stated that a serious loophole was being repaired and that the problem was attributed to Bruno Garcia and Ben Carman, researchers of the Bitcoin Reds.

The loophole involved a double TOTP identification bypass under Greenfield Basic Administration. After the update is released, BCCPay Server also changes the default status of Basic Administration to closed after the account was created to reduce risk exposure.

OpenSats subsequently disclosed that affected BTTCPay Server and LND components were used in its operating environment. The Agency stated that it had quickly completed the upgrade and that there had been no loss of donor funds, but that due to careful considerations, it had temporarily shut down the lightning network donation function.

AI compressing fixes window

The pseudonym developer Calle, who participated in the Bitcoin Reds, said that the team used Kimi K3 to dispose of most of the codes in the Bitcoin open source ecology within about two weeks. This reflects the fact that AI is changing the cost structure of the loopholes found to allow researchers to examine more suspicious code paths in a shorter period of time.

However, independent tests also show that Kimi K3 is not unlimited. A joint assessment by AI Security Institute and U. CAISI in the United Kingdom revealed that Kimi K3 scored 32 per cent on Expluit Bench, up from 24 per cent on GM-5.2. Of the 41 samples, however, it did not succeed in achieving any code implementation, while the model with a greater cyberattack capability tested could successfully complete an average of 20 samples.

This means that AI is currently better placed to scale up, rather than directly recognizing the availability of loopholes. The real pressure began to turn to the restoration chain: the ability of the project party to verify, patch and issue updates in a timely manner was becoming as important as the discovery of the hole itself.

Additional information:OpenSats has created a special Red Team Fund to subsidize token costs incurred by researchers using large models; and more than 40 digital asset agencies have called for front-line AI model access under controlled conditions for reviewed open-source defence teams.