AI Democratizes Hacking, Bitcoin Red Team White Hats Race in Speed-Based Attack-Defense Contest

marsbitPubblicato 2026-08-24Pubblicato ultima volta 2026-08-24

Introduzione

AI is democratizing powerful hacking tools, putting them in the hands of those with little cybersecurity expertise. Cryptocurrency developers are now in a race to find system vulnerabilities before attackers do. The Bitcoin Red Team, a group of 20-25 volunteers including anonymous developers like Calle, has formed to urgently address these AI-augmented security threats within the Bitcoin ecosystem. Calle emphasizes that while the Bitcoin core protocol itself is secure, the real risk lies in the wallets, applications, services, and other third-party software built on top of it—the software most users interact with. Incidents like the Coldcard wallet hack and the emergence of powerful Chinese AI models have accelerated their proactive security auditing efforts. The team both accepts audit requests from Bitcoin projects and proactively scans major open-source projects. They report found vulnerabilities to developers and refine their classification standards. Notably, Calle states the team frequently uses Chinese AI models over US counterparts, as the latter's strict safety guardrails often block cybersecurity research tasks, hindering their utility for finding or fixing vulnerabilities. Calle warns that AI is erasing the information asymmetry that previously protected some vulnerabilities. It lowers the technical barrier, allowing non-experts to exploit simple flaws. He describes the current state of Bitcoin software as "on fire" and believes the direct financial incentive of...

Author: Jason Nelson

Compiled by: Saoirse, Foresight News

Artificial intelligence has placed powerful hacking tools into the hands of a large number of people who lack cybersecurity expertise. Cryptocurrency developers have been forced into a race: they must find system vulnerabilities before attackers do.

The Bitcoin Red Team is one group taking on this challenge. The team's anonymous member, Bitcoin software developer Calle, said the team was formed to urgently respond to various AI-assisted security threats emerging within the Bitcoin ecosystem.

"Now, it's only a matter of time," Calle, who helps maintain the open-source protocol Cashu, told Decrypt. "The Bitcoin Red Team was formed so we can stay ahead of the attackers as much as possible."

According to Calle, the Bitcoin Red Team has 20–25 volunteers, many of whom choose to remain anonymous, such as Bitcoin privacy protocol developers Stu and Talip, as well as Cashu maintainer thesimplekid. Other team members include Bitcoin developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Bruno Garcia, a board member of the Vinteum Bitcoin research and development center.

Calle said that Rob Hamilton, CEO of the bitcoin insurance firm AnchorWatch, began investigating various Bitcoin projects after the Coldcard offline hardware wallet was hacked, and the Bitcoin Red Team gradually took shape in this context.

Calle emphasized that the team has not found issues with the Bitcoin protocol itself, but that risks are concentrated in wallets, applications, services, and other third-party software built on top of Bitcoin.

"The Bitcoin base layer is secure, but the software people use to transact in bitcoin isn't necessarily secure, and that's what the vast majority of users interact with," Calle said.

The Coldcard wallet breach, several attacks on Bitcoin-related services, and the release of more powerful Chinese AI models prompted Calle and other security researchers to dedicate themselves to this work and accelerate the review process.

"I think the arrival of Kimi K3 also brought a lot of turbulence to the cybersecurity space, giving both attackers and defenders unprecedented capabilities," he said.

Calle explained that the red team both receives security scan requests from Bitcoin projects and proactively hunts for vulnerabilities on its own.

"Many projects come to us and ask us to scan them, but we also take the initiative. Through our own investigations, we have pretty much covered all major open-source projects in the ecosystem. That is, even if a project comes to us for a scan now, chances are we've already scanned it."

The team reports its findings to the corresponding project developers and, based on their feedback, refines vulnerability classification standards and severity rating rules.

Chinese AI Models Fill the Tool Gap

Calle stated that Chinese AI models are used far more frequently than their US counterparts in the team's security work because US models' built-in safety guards block cybersecurity research-related tasks.

"The difference is very stark," he said.

In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using approximately 24,000 fake accounts to steal data from over 16 million Claude conversations via model distillation. The Trump administration warned in April that Chinese-linked entities were engaging in similar theft at an "industrial scale."

Calle believes that while cutting-edge US models still lead in overall capability, strict content restrictions diminish their utility in security-related work.

"It's undeniable that top US models still lead the world in general intelligence, but they are heavily guardrailed, which limits their use, especially in cybersecurity."

Before joining the red team, Calle personally encountered these limitations. He said US AI models sometimes refuse to help find vulnerabilities; they even decline to assist in fixing vulnerabilities already confirmed by developers, prompting him to switch to Chinese AI models.

"Bitcoin Is Burning"

Earlier this month, Calle used the phrase "Bitcoin is burning" to describe the increasingly severe security threats facing Bitcoin software, referring here to wallets, exchanges, Lightning Network implementations, and the entire ecosystem of peripheral software built on Bitcoin.

Calle believes attackers are already using AI to find and exploit vulnerabilities. But to avoid giving malicious hackers ideas, he declined to elaborate on their specific methods.

He also warned that in the past, some software vulnerabilities were inaccessible to attackers due to technical barriers or lack of information; AI is now eroding that barrier.

"There are no secrets in software anymore. The old model of security through obscurity, of security through withheld details, is over. Its time has ended," Calle said.

AI has also lowered the technical barrier for exploiting vulnerabilities.

"Now, someone without the relevant skills can use AI to carry out an attack on a simple vulnerability from start to finish. This capability AI gives to ordinary people completely changes the attack-defense landscape."

Calle argues that because cryptocurrency offers direct financial gain, providing attackers with a strong monetary incentive, Bitcoin will encounter this shift earlier than other industries.

"Digital money on the internet is the prime target for attackers. We are at the beginning of a massive shift across the entire computing industry, and I am certain other industries will face the same kind of security issues we are dealing with now in the future."

Domande pertinenti

QWhat is the main goal of the Bitcoin Red Team as described in the article?

AThe main goal of the Bitcoin Red Team is to race ahead of attackers by proactively finding and addressing security vulnerabilities in the Bitcoin software ecosystem (like wallets and applications), especially those threats being accelerated by AI tools.

QAccording to the article, why does Calle say 'Bitcoin is burning'?

ACalle uses the phrase 'Bitcoin is burning' to describe the increasingly severe security threats faced by the Bitcoin software ecosystem, including wallets, exchanges, and layer-2 solutions, as AI lowers the barrier for attacks.

QWhy does the Bitcoin Red Team favor Chinese AI models over American ones for their security work?

AThe team favors Chinese AI models because American models often have strict safety guardrails that block or refuse tasks related to cybersecurity research, such as finding or helping to fix vulnerabilities, making them less practical for this specific use case.

QWhat specific event helped catalyze the formation of the Bitcoin Red Team?

AThe formation of the Bitcoin Red Team was catalyzed in part by the hacking incident involving the Coldcard hardware wallet, which prompted security researchers to start scrutinizing various Bitcoin projects more urgently.

QHow is AI changing the landscape of cybersecurity attacks according to Calle?

AAI is democratizing hacking by lowering the technical barrier. It allows individuals without deep expertise to find and exploit simple vulnerabilities, eliminating the security-through-obscurity model and shifting the dynamics of the attack-defense balance.

Letture associate

Grayscale Reassesses Zcash: In the Era of AI Surveillance, What is Financial Privacy Worth?

Grayscale Research reevaluates Zcash (ZEC) in the context of AI-powered financial surveillance. The report posits that stablecoins, transparent blockchains, and AI analytics tools are increasing the traceability of digital finance, potentially reigniting mainstream demand for financial privacy as a core monetary attribute. While AI could drive a third wave of privacy concern, Zcash's investment thesis hinges on whether this theoretical demand translates into sustained adoption. Zcash, operational for nearly a decade, uses zero-knowledge proofs to offer users a choice between transparent and shielded transactions, placing control of information disclosure back in users' hands. Recent infrastructure improvements—like wallet enhancements, mining pool expansions, and protocol upgrades—have reduced usability barriers. On-chain data shows shielded transactions comprise ~90% of transaction count, with ~25% of circulating ZEC in shielded pools, indicating existing use. However, significant risks remain. These include regulatory hurdles for exchanges and custodians dealing with shielded assets, past protocol vulnerabilities (theoretical, now patched), long-term quantum computing threats, and execution risks for future scalability upgrades. Grayscale's analysis suggests ZEC's current low market share (~0.6% of the "digital currency" crypto sector) offers valuation upside *if* the market reprices privacy. A scenario analysis notes that capturing 5% of this sector could imply a ~9x valuation increase, though this is a simplified sensitivity test, not a price target. Ultimately, Zcash's opportunity lies in the unresolved question: in an AI-monitored era, what price will the market assign to financial privacy? Validating the thesis requires monitoring growth in real shielded usage, wallet usability, upgrade timelines, and regulatory accessibility, not just price appreciation.

marsbit35 min fa

Grayscale Reassesses Zcash: In the Era of AI Surveillance, What is Financial Privacy Worth?

marsbit35 min fa

Foreign Capital Sells Off $29 Billion in Short-Term US Treasuries, Why is the US Betting on Stablecoins to "Take Over"?

In June, foreign investors netted $133.5 billion into U.S. financial markets but simultaneously sold $29 billion in short-term U.S. Treasury bills. This divergence highlights a strong preference for U.S. equities over government debt. While overseas buyers purchased $181.4 billion in stocks, demand for Treasuries weakened significantly. This trend explains why the U.S. is looking to stablecoins as a potential new source of demand for its debt. Stablecoin issuers like Tether and Circle back their tokens primarily with highly liquid assets, including short-term Treasuries. As users buy stablecoins, issuers convert that dollar demand into Treasury purchases. Recent U.S. legislative efforts, such as the proposed rules under the *GENIUS Act*, formalize this by mandating stablecoin reserves be held in assets like cash and short-term Treasuries. Currently, stablecoins represent a substantial existing buyer base. For instance, Tether alone held nearly $115 billion in direct T-bill exposure in Q2. However, recent stablecoin supply growth has been minimal and does not account for the $29 billion sell-off by foreign investors in June. For stablecoins to act as a meaningful counterbalance to waning foreign demand, their circulating supply would need to expand significantly. The next TIC report will be crucial to monitor whether foreign selling continues and if stablecoin growth begins to fill the demand gap. Ultimately, the U.S. is strategically positioning the regulated stablecoin sector as a potential new pillar of demand for its government debt.

marsbit56 min fa

Foreign Capital Sells Off $29 Billion in Short-Term US Treasuries, Why is the US Betting on Stablecoins to "Take Over"?

marsbit56 min fa

Trading

Spot
活动图片