What happened with the Bitcoin Red Team?Rob Hamilton, CEO of AnchorWatch, initiated a volunteer group called the Bitcoin Red Team, aiming to conduct AI-driven security audits on open-source Bitcoin repositories. Their work became vital following a serious security incident related to Coldcard hardware wallets that allowed for the unauthorized theft of over 1,000 BTC.
The Red Team employed cutting-edge AI technologies to systematically analyze numerous Bitcoin-related repositories, achieving rapid results. In just 30 hours, they scanned over 390 repositories and identified nearly 5,000 issues. Among these findings, 85 were deemed critical while over 635 categorized as high severity. The reproducibility of these vulnerabilities was credible, with about one in five being independently confirmed as legitimate.
How much did this initiative cost?The total expenses associated with AI computing for this project fell within the range of $20,000 to $40,000. The team utilized a variety of AI models, including Kimi K3 from Moonshot AI, which facilitated a significant portion of their analyses. Other models employed included OpenAI's Cyber Harness and options from Anthropic and GLM. The results were shared with the maintainers of the respective repositories, adhering to standard responsible disclosure protocols.
What challenges did the Red Team face?Despite having met all requirements for access to AI tools, the team faced obstructions. Both OpenAI and Anthropic imposed restrictions during critical phases of their project. Hamilton had been fully verified and was compliant, yet access was revoked, leading him to seek alternatives. This restriction led to a transition towards using the Kimi K3 model from a Chinese firm, demonstrating an ironic turn of events where U.S.-based researchers felt compelled to migrate to non-U.S. models to continue their work on securing Bitcoin infrastructure.
The situation drew public attention, prompting OpenAI to reconsider access for the team later, once they garnered media visibility. This highlights ongoing regulatory challenges and implications for researchers in the U.S. seeking to innovate and apply advanced AI for legitimate security purposes.