AI Has Made Bitcoin Software a Target—This Group Is Fighting Back
- In an interview with Decrypt, Bitcoin Red Team member Calle said Chinese AI models are used far more than U.S. models for security research because American models often block cybersecurity-related requests.
- The group has proactively scanned much of Bitcoin’s significant open-source ecosystem and works directly with projects to identify and fix vulnerabilities.
- Calle warned that AI allows people without advanced security expertise to carry out exploits from beginning to end.
AI is putting powerful hacking capabilities in the hands of people with little cybersecurity expertise, forcing crypto developers into a race to find vulnerabilities before attackers exploit them.
One group taking on that challenge is the Bitcoin Red Team, whose pseudonymous member and Bitcoin software developer Calle said formed as an emergency effort to find AI-assisted security threats across the Bitcoin ecosystem.

“At this point, it is a question about time,” Calle, who helps maintain the open-source protocol Cashu, told Decrypt. “The reason why the Bitcoin Red Team exists right now is because we need to get ahead of the attackers as fast as possible.”
The Bitcoin Red Team consists of about 20 to 25 volunteers, according to Calle, many of whom prefer to remain pseudonymous, such as Bitcoin privacy protocol developers Stu, Talip, and fellow Cashu dev thesimplekid. Others in the group include Bitcoin developers Ben Carmen, Daniela Brozzoni, and James O’Beirne, and Vinteum Bitcoin R&D Center board member Bruno Garcia.
Bitcoin Red Team Update:
We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.
We have done over a dozen…
— Rob Hamilton 🟥 (@Rob1Ham) August 4, 2026
Calle said the Bitcoin Red Team began taking shape after CEO of Bitcoin Insurance firm AnchorWatch Rob Hamilton started examining Bitcoin projects following the Coldcard air-gapped wallet hack.
While Calle stressed that the group has found no issues in the Bitcoin protocol itself, the concern he said instead lies with applications, wallets, services, and other software built around Bitcoin.
“Although Bitcoin itself is secure, the software that we’re using to transact with Bitcoin may not be, and that is what most people interface with anyway,” Calle said.
The Coldcard exploit, attacks on other Bitcoin services, and the release of more powerful Chinese AI models pushed Calle and other security researchers to join the effort and move quickly.
“I think the arrival of Kimi K3 has also caused a lot of chaos in the cybersecurity realm because it gave attackers as well as defenders unprecedented power,” he said.
As Calle explained, the Red Team receives requests from Bitcoin projects seeking security scans but also searches for vulnerabilities on its own.
“We get a bunch of inbound requests from projects that want to be scanned, but we act proactively, and we’ve covered almost the entire significant open-source ecosystem by our own sweeps already,” Calle said. “So even if you come and ask us to scan your project, we’ve probably scanned it already.”
The group shares its findings with affected developers and uses their feedback to improve its vulnerability classifications and severity ratings.
Chinese models fill the gap
Chinese AI models are used far more than their U.S. counterparts for the group’s security work because guardrails on American models can block cybersecurity research, Calle said.
“It’s not even close,” he said.
In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation, while the Trump administration warned in April that Chinese entities were conducting similar campaigns on an “industrial scale.”

While Calle said U.S. frontier models remain arguably more capable overall, their restrictions can limit their usefulness for security-sensitive work.
“Although U.S.-based frontier models are still arguably more intelligent than any other models out there in the world, they all come with heavy guardrailing, which limits their use, especially in the cybersecurity realm,” he said.
Calle encountered those restrictions before joining the Red Team. He said U.S. models sometimes refused to help find vulnerabilities and, in some cases, would not assist with fixing vulnerabilities that developers had already identified, leading him to switch to Chinese AI models.
‘Bitcoin is burning’
Earlier this month, Calle described the growing security threat facing Bitcoin software as “Bitcoin is burning,” referring to the wider ecosystem of wallets, exchanges, Lightning implementations and other software built around it.
Calle believes attackers are already using AI to find and exploit vulnerabilities, but avoids discussing their methods in detail out of concern that doing so could give malicious hackers ideas.
He also warned that AI is eroding the information advantage that once kept some software vulnerabilities out of reach of less-skilled attackers.
“I think that there are no secrets anymore in software,” Calle said. “There is no information asymmetry that was previously being used to kind of create security theater or security through obscurity. Those times are over.”
AI has also lowered the technical barrier to exploiting vulnerable software, he said.
“Simple exploits can now be completed end to end by someone who doesn’t know how to do it without AI,” Calle said. “So AI gave people a form of power that has completely changed the playing field.”
Bitcoin may be confronting that shift earlier than other industries because attackers have a direct financial incentive to target cryptocurrency, Calle said.
“The first thing that, as an attacker, you would want to attack is internet money,” he said. “So we are the beginning of a larger change in society or in computer systems in general, and I’m convinced that other industries will experience the same thing as we do right now later.”
You may also like
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- January 2024
- December 2023
- January 2023
- December 2022
- January 2022
- December 2021
- January 2021
- December 2020
- December 2019
Leave a Reply
You must be logged in to post a comment.