AI is putting powerful hacking capabilities in the hands of people with little cybersecurity expertise, forcing crypto developers into a race to find vulnerabilities before attackers exploit them.
Myriad: Bitcoin price next move? Click to make your prediction."At this point, it is a question about time,” Calle, who helps maintain the open-source protocol Cashu, told Decrypt. “The reason why the Bitcoin Red Team exists right now is because we need to get ahead of the attackers as fast as possible.”
Bitcoin Red Team Update:
We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of.
We have done over a dozen…
"Although Bitcoin itself is secure, the software that we're using to transact with Bitcoin may not be, and that is what most people interface with anyway," Calle said.
The Coldcard exploit, attacks on other Bitcoin services, and the release of more powerful Chinese AI models pushed Calle and other security researchers to join the effort and move quickly.
As Calle explained, the Red Team receives requests from Bitcoin projects seeking security scans but also searches for vulnerabilities on its own.
"We get a bunch of inbound requests from projects that want to be scanned, but we act proactively, and we've covered almost the entire significant open-source ecosystem by our own sweeps already," Calle said. "So even if you come and ask us to scan your project, we've probably scanned it already."
The group shares its findings with affected developers and uses their feedback to improve its vulnerability classifications and severity ratings.
Chinese models fill the gapChinese AI models are used far more than their U.S. counterparts for the group's security work because guardrails on American models can block cybersecurity research, Calle said.
“It's not even close," he said.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.While Calle said U.S. frontier models remain arguably more capable overall, their restrictions can limit their usefulness for security-sensitive work.
"Although U.S.-based frontier models are still arguably more intelligent than any other models out there in the world, they all come with heavy guardrailing, which limits their use, especially in the cybersecurity realm," he said.
Calle encountered those restrictions before joining the Red Team. He said U.S. models sometimes refused to help find vulnerabilities and, in some cases, would not assist with fixing vulnerabilities that developers had already identified, leading him to switch to Chinese AI models.
'Bitcoin is burning'Calle believes attackers are already using AI to find and exploit vulnerabilities, but avoids discussing their methods in detail out of concern that doing so could give malicious hackers ideas.
He also warned that AI is eroding the information advantage that once kept some software vulnerabilities out of reach of less-skilled attackers.
"I think that there are no secrets anymore in software," Calle said. "There is no information asymmetry that was previously being used to kind of create security theater or security through obscurity. Those times are over."
AI has also lowered the technical barrier to exploiting vulnerable software, he said.
"Simple exploits can now be completed end to end by someone who doesn't know how to do it without AI," Calle said. "So AI gave people a form of power that has completely changed the playing field."
Bitcoin may be confronting that shift earlier than other industries because attackers have a direct financial incentive to target cryptocurrency, Calle said.
"The first thing that, as an attacker, you would want to attack is internet money," he said. "So we are the beginning of a larger change in society or in computer systems in general, and I'm convinced that other industries will experience the same thing as we do right now later."



















