A team of over 20 anonymous members is combating AI-assisted attacks, relying on Chinese AI models to fill the gaps left by American models' "guardrails".
Written by: Jason Nelson
Compiled by: Saoirse, Foresight News
Artificial intelligence has put powerful hacking tools into the hands of many who lack cybersecurity expertise. Cryptocurrency developers are forced to enter a race: they must find system vulnerabilities before attackers do.
The Bitcoin Red Team is the group rising to this challenge. Calle, an anonymous member and Bitcoin software developer, stated that the team was formed to urgently respond to various AI-assisted security threats within the Bitcoin ecosystem.
"Now, it’s just a matter of time," Calle, who is involved in maintaining the open-source protocol Cashu, told Decrypt. "The reason for the establishment of the Bitcoin Red Team is that we want to stay ahead of the attackers as much as possible."
According to Calle, the Bitcoin Red Team consists of 20-25 volunteers, many of whom choose to remain anonymous, including Bitcoin privacy protocol developers Stu, Talip, and thesimplekid, who also maintains Cashu. Other team members include Bitcoin developers Ben Carmen, Daniela Brozzoni, James O'Beirne, and Bruno Garcia, a board member of the Vinteum Bitcoin Research Center.
Calle noted that Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch, began investigating various Bitcoin projects after the Coldcard offline hardware wallet was hacked, leading to the gradual formation of the Bitcoin Red Team.
Calle emphasized that the team has not found issues with the Bitcoin underlying protocol itself, but risks are concentrated in wallets, various applications, services, and other third-party software built on Bitcoin.
"The Bitcoin underlying protocol itself is secure, but the various software that ordinary people use to conduct Bitcoin transactions may not be secure, and most users are precisely interacting with these upper-layer software," Calle said.
The hacking of the Coldcard wallet, multiple attacks on Bitcoin-related services, and the emergence of more powerful Chinese AI models have prompted Calle and other security researchers to engage in this work and accelerate the investigation process.
"I believe the emergence of Kimi K3 has also brought a lot of turmoil to the cybersecurity field, giving both attackers and defenders unprecedented capabilities," he stated.
Calle explained that the red team receives security scanning requests from Bitcoin projects while also proactively searching for vulnerabilities.
"Many projects will actively reach out to us for scanning, but we also take the initiative. Through our own investigations, we have almost covered all significant open-source projects within the ecosystem. This means that even if a project comes to us for scanning, we may have already scanned it before," he said.
The team provides feedback on discovered vulnerabilities to the corresponding project developers and optimizes vulnerability classification standards and risk assessment rules based on the developers' feedback.
Calle stated that during the team's security-related work, the frequency of using Chinese AI models far exceeds that of American counterparts, as the built-in security mechanisms of American models intercept tasks related to cybersecurity research.
"The difference is very obvious," he said.
In February this year, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI, and MiniMax of using about 24,000 fake accounts to steal over 16 million Claude conversation data through model distillation technology. The Trump administration issued a warning in April, stating that Chinese entities are conducting similar thefts on an "industrial scale."
Calle believes that although the comprehensive capabilities of American cutting-edge large models are still leading, the stringent content restrictions have weakened their practicality in security-related work.
"It is undeniable that the top American large models still lead the world in comprehensive intelligence levels, but they all have heavy protective restrictions that limit the models' uses, especially in the field of cybersecurity," he said.
Before joining the red team, Calle personally encountered such restrictions. He said that American AI models sometimes refuse to assist in finding vulnerabilities; even when facing vulnerabilities already confirmed by developers, the models are unwilling to provide repair assistance, prompting him to turn to Chinese AI models.
Earlier this month, Calle described the increasingly severe security threats facing Bitcoin software as "Bitcoin is burning," referring to wallets, exchanges, Lightning Network implementations, and all peripheral software ecosystems built on Bitcoin.
Calle believes that attackers are already using artificial intelligence to find and exploit vulnerabilities. However, to avoid providing malicious hackers with attack ideas, he declined to elaborate on the specific methods used by attackers.
He also warned that in the past, some software vulnerabilities were inaccessible to technically insufficient attackers due to information barriers; however, artificial intelligence is dissolving this layer of information barrier.
"There are no secrets left in the software field. The security disguises that relied on information asymmetry and the vague security achieved by not disclosing details are no longer effective; their era has ended," Calle said.
Artificial intelligence has also lowered the technical threshold for exploiting vulnerabilities.
"Now, a person who does not have relevant technical skills can use AI to complete the exploitation of simple vulnerabilities from start to finish. This ability granted to ordinary people by AI has completely rewritten the landscape of the offense and defense game," he said.
Calle believes that cryptocurrencies can directly bring economic benefits, and attackers have strong monetary motives, so Bitcoin will encounter this change earlier than other industries.
"The primary target for attackers is internet digital currency. We are at the beginning of a major transformation in the entire computer industry, and I am confident that other industries will also face similar security issues that we are currently facing in the future."
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.













Global markets consolidated over the weekend. SanDisk benefited from strong AI data-center demand, long-term customer contracts, and improving expectations for the storage supply-demand balance. SpaceX-related names also performed well. Precious metals held near elevated levels, while Bitcoin moved toward $75,000 and continued to support crypto-financial stocks. Markets are now focused on Pinduoduo’s earnings and the impact of future rate expectations on technology and small-cap valuations.
















