Bitcoin itself may be mathematically sound, but the software ecosystem built around it is under siege. According to reporting by Decrypt, a growing volunteer group called the Bitcoin Red Team is racing to identify vulnerabilities in wallets, exchanges, and other applications before AI-assisted attackers exploit them — a race the group’s members believe they cannot afford to lose.
The threat is immediate. Artificial intelligence has democratized vulnerability discovery in ways that traditional security research never could. Attackers without specialized expertise can now identify and execute exploits from beginning to end. That capability shift has forced Bitcoin developers into what amounts to a perpetual security sprint.
The Bitcoin Ecosystem Catches Fire
Calle, a Bitcoin developer and pseudonymous member of the Red Team who maintains the open-source Cashu protocol, described the situation bluntly to Decrypt: “Bitcoin is burning.” He was not referring to the protocol itself, which has never experienced a fundamental break. Rather, he meant the sprawling ecosystem of wallets, exchanges, hardware devices, and Lightning Network implementations that users rely on to actually move Bitcoin.
The urgency crystallized after several high-profile incidents. The Coldcard air-gapped wallet hack and subsequent attacks on Bitcoin services convinced security researchers that reactive patching was no longer viable. When more powerful Chinese AI models became widely available, the calculus shifted entirely.
“At this point, it is a question about time,” Calle told Decrypt. “The reason why the Bitcoin Red Team exists right now is because we need to get ahead of the attackers as fast as possible.”
A Volunteer Force Takes the Field
The Red Team comprises roughly 20 to 25 volunteers, many operating under pseudonyms to protect their privacy. Known members include Bitcoin developers Ben Carmen, Daniela Brozzoni, and James O’Beirne, alongside privacy-focused developers Stu and Talip. Rob Hamilton, CEO of Bitcoin insurance firm AnchorWatch, catalyzed the group’s formation after examining Bitcoin projects in the wake of the Coldcard exploit.
The group has already scanned much of Bitcoin’s significant open-source ecosystem proactively. They do not wait for projects to request audits — they hunt for weaknesses themselves, then coordinate disclosure with developers and track remediation efforts.
The funding situation reflects both urgency and confidence. Hamilton announced in August 2026 that the group had spent roughly $20,000 across various security services, with funding already secured. The operational tempo is sustained: around-the-clock vulnerability research aimed at staying ahead of attackers.
Why Chinese AI Models Dominate Security Work
One inconvenient truth emerged from the Red Team’s operations: Chinese AI models are far more useful for Bitcoin security research than American counterparts.
“It’s not even close,” Calle said when asked about the gap between U.S. and Chinese AI tools. American frontier models like OpenAI’s systems and Claude come with restrictive guardrails designed to prevent misuse. Those same safeguards block legitimate security research. U.S. models sometimes refuse to help identify vulnerabilities or assist in fixing already-discovered flaws.
Chinese AI labs have been accused of conducting industrial-scale operations to extract training data from restricted American models, but their own systems lack the guardrails that constrain security work. For researchers trying to move quickly, the choice is practical.
“Although U.S.-based frontier models are still arguably more intelligent than any other models out there in the world, they all come with heavy guardrailing, which limits their use, especially in the cybersecurity realm,” Calle explained.
This dynamic has broader implications. It means Bitcoin developers depend on tools built outside U.S. regulatory oversight. It also highlights a tension within AI safety: restrictions meant to prevent harm can inadvertently slow legitimate defensive research.
The Information Asymmetry is Gone
What troubles security researchers most is not any single vulnerability, but the structural shift AI has enabled. Traditional software security relied partly on obscurity — the idea that fewer people understood the attack surface, so fewer people could exploit it. That information asymmetry is dead.
“I think that there are no secrets anymore in software,” Calle said. “There is no information asymmetry that was previously being used to create security theater or security through obscurity. Those times are over.”
AI has compressed the skill curve. A person without advanced security training can now use AI as a personal security consultant, walking through exploit development from reconnaissance to delivery. That capability has historically belonged only to specialists.
“Simple exploits can now be completed end to end by someone who doesn’t know how to do it without AI,” Calle observed. “So AI gave people a form of power that has completely changed the playing field.”
Why Bitcoin Faces This Crisis First
Bitcoin and cryptocurrency more broadly are experiencing this security shock earlier than most industries, Calle believes, because the financial incentives for attackers are immediate and massive. Someone with knowledge of a vulnerability in a widely-used Bitcoin wallet can potentially steal funds directly. That level of immediate ROI does not exist in many other software domains.
“The first thing that, as an attacker, you would want to attack is internet money,” Calle said. “So we are the beginning of a larger change in society or in computer systems in general, and I’m convinced that other industries will experience the same thing as we do right now later.”
The Red Team’s work is ultimately defensive — finding bugs before attackers do. But Calle avoided detailing specific attack methods, wary of inadvertently arming malicious hackers with new ideas. What is clear is that the Bitcoin ecosystem cannot rely on security through obscurity or the assumption that complex exploits remain out of reach of unmotivated attackers.
The race continues. So far, the Red Team has found no flaws in Bitcoin’s core protocol. The vulnerabilities lie in the surrounding applications — the software that users actually interact with. Fixing those before AI-assisted attacks arrive at scale remains the urgent task ahead.