Skip to content

InvestNot yet confirmed elsewhere1 publisher2 min readPublished

The $20,000 red team: US guardrails push Bitcoin's defenders onto Chinese models

A volunteer group says it has swept almost all of Bitcoin's open-source ecosystem for AI-assisted exploits, and that American models' refusals made Chinese ones the default tool.

The Investor · Invest desk

How we use AISend a correction

What happened

  • A volunteer group called the Bitcoin Red Team formed as an emergency effort to find AI-assisted security threats across Bitcoin's software ecosystem.
  • Its members say they have already swept almost the entire significant open-source Bitcoin ecosystem without waiting to be asked.
  • Calle says nothing has been found in the Bitcoin protocol itself; the problems sit in wallets, applications and services built on top.
  • Chinese models do far more of the group's security work than American ones, Calle told Decrypt, because US models block cybersecurity requests.
  • Rob Hamilton put the effort's spend at about $20,000 across services in an August 4 update and said its funding is already covered.

Why it matters

  • constraint Any custodian or exchange whose vendor policy bars Chinese-hosted inference is committing its defenders to the tool that declines part of the job.
  • exposure Wallet code maintained by one or two people was protected partly by the shortage of readers capable of attacking it, and that shortage is what is going away.
  • cost The bill for ecosystem-wide scanning is currently being carried by donation-scale money and volunteer time, so no project has to price this risk into its own budget.
  • contradiction By the group's own ranking the smartest models and the usable ones are different vendors, which turns a capability argument into a compliance one.

A refusal is not a control, it is a routing decision. Calle told Decrypt that American models sometimes declined to help him locate vulnerabilities, and in some cases would not help fix ones that had already been found [4]. Nobody appeals that. They open a different tab.

What follows is a split between the people who can make that move and the people who cannot. The group's trigger, by Calle's account, was AnchorWatch chief executive Rob Hamilton going through Bitcoin projects after the Coldcard air-gapped wallet hack [7], and its working output is a loop with maintainers whose feedback it uses to sharpen its own severity ratings [11]. That is unfunded and unaccountable, and it is also fast. An insurer or an exchange attempting the same sweeps under a written model-use policy is slower by construction, and pays more for inference that Calle himself says will refuse some of the questions [4].

Then the arithmetic. Hamilton's spend figure, spread across the roster, comes to roughly $800 to $1,000 per participant [16]. Small money for the breadth being claimed, and it points at where the scarcity actually sits: not compute, but the two dozen or so people who can tell a real finding from noise [12].

Calle credits the release of Kimi K3 with upending his field, saying it "gave attackers as well as defenders unprecedented power" [8]. The awkward part is provenance. Anthropic said in February that DeepSeek, Moonshot AI and MiniMax used roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation [9], which works out to about 667 exchanges per account [17], a pattern closer to patient bulk collection than to a few heavy users. The Trump administration said in April that Chinese entities were running campaigns of that kind at industrial scale [10]. If those accounts hold, the models now doing Bitcoin's defensive scanning were assembled in part from the outputs of the model that will not answer the question.

One caution on the whole picture. The usage claim rests on a single pseudonymous member speaking to one publication, with no metered comparison offered [2], and the only public number attached to the effort is a spend total posted by the person who started it [6]. Take the direction and discount the magnitude.

The narrow version of the problem, for anyone drafting a security line item, is that the permitted tool and the effective tool are no longer the same vendor, and the volunteers have already shown which one gets used when there is no procurement process to satisfy.

What to watch

  • Whether any regulated custodian or exchange publishes a model-use policy that explicitly permits, or bans, Chinese-hosted inference for security testing.
  • Whether US labs open a verified-researcher path for vulnerability discovery and remediation work that currently gets refused.
  • Whether the Bitcoin Red Team publishes a checkable tally of findings and severities rather than a spend figure and a coverage claim.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence28
Adoption32
Hype gap+34
Incentives66
Confidence44
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Calle said the Bitcoin Red Team formed as an emergency effort to find AI-assisted security threats across the Bitcoin ecosystem, and exists to get ahead of attackers as fast as possible.

    ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source
  2. [2]

    Calle said Chinese AI models are used far more than U.S. models for the group's security research because American models often block cybersecurity-related requests, adding: "It's not even close."

    ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source
  3. [3]

    Calle said U.S.-based frontier models are still arguably more intelligent than any other models in the world, but come with heavy guardrailing that limits their use in the cybersecurity realm.

    ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. decrypt.co

    1 article · August 22, 2026

    AI Has Made Bitcoin Software a Target—This Group Is Fighting Back

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories