Author: Jason Nelson
Compiled by: Saoirse, Foresight News
Artificial intelligence has placed powerful hacking tools into the hands of a large number of people who lack cybersecurity expertise. Cryptocurrency developers have been forced into a race: they must find system vulnerabilities before attackers do.
The Bitcoin Red Team is one group taking on this challenge. The team's anonymous member, Bitcoin software developer Calle, said the team was formed to urgently respond to various AI-assisted security threats emerging within the Bitcoin ecosystem.
"Now, it's only a matter of time," Calle, who helps maintain the open-source protocol Cashu, told Decrypt. "The Bitcoin Red Team was formed so we can stay ahead of the attackers as much as possible."
According to Calle, the Bitcoin Red Team has 20–25 volunteers, many of whom choose to remain anonymous, such as Bitcoin privacy protocol developers Stu and Talip, as well as Cashu maintainer thesimplekid. Other team members include Bitcoin developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Bruno Garcia, a board member of the Vinteum Bitcoin research and development center.

Calle said that Rob Hamilton, CEO of the bitcoin insurance firm AnchorWatch, began investigating various Bitcoin projects after the Coldcard offline hardware wallet was hacked, and the Bitcoin Red Team gradually took shape in this context.
Calle emphasized that the team has not found issues with the Bitcoin protocol itself, but that risks are concentrated in wallets, applications, services, and other third-party software built on top of Bitcoin.
"The Bitcoin base layer is secure, but the software people use to transact in bitcoin isn't necessarily secure, and that's what the vast majority of users interact with," Calle said.
The Coldcard wallet breach, several attacks on Bitcoin-related services, and the release of more powerful Chinese AI models prompted Calle and other security researchers to dedicate themselves to this work and accelerate the review process.
"I think the arrival of Kimi K3 also brought a lot of turbulence to the cybersecurity space, giving both attackers and defenders unprecedented capabilities," he said.
Calle explained that the red team both receives security scan requests from Bitcoin projects and proactively hunts for vulnerabilities on its own.
"Many projects come to us and ask us to scan them, but we also take the initiative. Through our own investigations, we have pretty much covered all major open-source projects in the ecosystem. That is, even if a project comes to us for a scan now, chances are we've already scanned it."
The team reports its findings to the corresponding project developers and, based on their feedback, refines vulnerability classification standards and severity rating rules.
Chinese AI Models Fill the Tool Gap
Calle stated that Chinese AI models are used far more frequently than their US counterparts in the team's security work because US models' built-in safety guards block cybersecurity research-related tasks.
"The difference is very stark," he said.
In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using approximately 24,000 fake accounts to steal data from over 16 million Claude conversations via model distillation. The Trump administration warned in April that Chinese-linked entities were engaging in similar theft at an "industrial scale."
Calle believes that while cutting-edge US models still lead in overall capability, strict content restrictions diminish their utility in security-related work.
"It's undeniable that top US models still lead the world in general intelligence, but they are heavily guardrailed, which limits their use, especially in cybersecurity."
Before joining the red team, Calle personally encountered these limitations. He said US AI models sometimes refuse to help find vulnerabilities; they even decline to assist in fixing vulnerabilities already confirmed by developers, prompting him to switch to Chinese AI models.
"Bitcoin Is Burning"
Earlier this month, Calle used the phrase "Bitcoin is burning" to describe the increasingly severe security threats facing Bitcoin software, referring here to wallets, exchanges, Lightning Network implementations, and the entire ecosystem of peripheral software built on Bitcoin.
Calle believes attackers are already using AI to find and exploit vulnerabilities. But to avoid giving malicious hackers ideas, he declined to elaborate on their specific methods.
He also warned that in the past, some software vulnerabilities were inaccessible to attackers due to technical barriers or lack of information; AI is now eroding that barrier.
"There are no secrets in software anymore. The old model of security through obscurity, of security through withheld details, is over. Its time has ended," Calle said.
AI has also lowered the technical barrier for exploiting vulnerabilities.
"Now, someone without the relevant skills can use AI to carry out an attack on a simple vulnerability from start to finish. This capability AI gives to ordinary people completely changes the attack-defense landscape."
Calle argues that because cryptocurrency offers direct financial gain, providing attackers with a strong monetary incentive, Bitcoin will encounter this shift earlier than other industries.
"Digital money on the internet is the prime target for attackers. We are at the beginning of a massive shift across the entire computing industry, and I am certain other industries will face the same kind of security issues we are dealing with now in the future."





