InvestNot yet confirmed elsewhere1 publisher2 min readPublished
The $20,000 red team: US guardrails push Bitcoin's defenders onto Chinese models
A volunteer group says it has swept almost all of Bitcoin's open-source ecosystem for AI-assisted exploits, and that American models' refusals made Chinese ones the default tool.
The Investor · Invest desk
What happened
- A volunteer group called the Bitcoin Red Team formed as an emergency effort to find AI-assisted security threats across Bitcoin's software ecosystem.
- Its members say they have already swept almost the entire significant open-source Bitcoin ecosystem without waiting to be asked.
- Calle says nothing has been found in the Bitcoin protocol itself; the problems sit in wallets, applications and services built on top.
- Chinese models do far more of the group's security work than American ones, Calle told Decrypt, because US models block cybersecurity requests.
- Rob Hamilton put the effort's spend at about $20,000 across services in an August 4 update and said its funding is already covered.
Why it matters
- constraint Any custodian or exchange whose vendor policy bars Chinese-hosted inference is committing its defenders to the tool that declines part of the job.
- exposure Wallet code maintained by one or two people was protected partly by the shortage of readers capable of attacking it, and that shortage is what is going away.
- cost The bill for ecosystem-wide scanning is currently being carried by donation-scale money and volunteer time, so no project has to price this risk into its own budget.
- contradiction By the group's own ranking the smartest models and the usable ones are different vendors, which turns a capability argument into a compliance one.
A refusal is not a control, it is a routing decision. Calle told Decrypt that American models sometimes declined to help him locate vulnerabilities, and in some cases would not help fix ones that had already been found [4]. Nobody appeals that. They open a different tab.
What follows is a split between the people who can make that move and the people who cannot. The group's trigger, by Calle's account, was AnchorWatch chief executive Rob Hamilton going through Bitcoin projects after the Coldcard air-gapped wallet hack [7], and its working output is a loop with maintainers whose feedback it uses to sharpen its own severity ratings [11]. That is unfunded and unaccountable, and it is also fast. An insurer or an exchange attempting the same sweeps under a written model-use policy is slower by construction, and pays more for inference that Calle himself says will refuse some of the questions [4].
Then the arithmetic. Hamilton's spend figure, spread across the roster, comes to roughly $800 to $1,000 per participant [16]. Small money for the breadth being claimed, and it points at where the scarcity actually sits: not compute, but the two dozen or so people who can tell a real finding from noise [12].
Calle credits the release of Kimi K3 with upending his field, saying it "gave attackers as well as defenders unprecedented power" [8]. The awkward part is provenance. Anthropic said in February that DeepSeek, Moonshot AI and MiniMax used roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation [9], which works out to about 667 exchanges per account [17], a pattern closer to patient bulk collection than to a few heavy users. The Trump administration said in April that Chinese entities were running campaigns of that kind at industrial scale [10]. If those accounts hold, the models now doing Bitcoin's defensive scanning were assembled in part from the outputs of the model that will not answer the question.
One caution on the whole picture. The usage claim rests on a single pseudonymous member speaking to one publication, with no metered comparison offered [2], and the only public number attached to the effort is a spend total posted by the person who started it [6]. Take the direction and discount the magnitude.
The narrow version of the problem, for anyone drafting a security line item, is that the permitted tool and the effective tool are no longer the same vendor, and the volunteers have already shown which one gets used when there is no procurement process to satisfy.
What to watch
- Whether any regulated custodian or exchange publishes a model-use policy that explicitly permits, or bans, Chinese-hosted inference for security testing.
- Whether US labs open a verified-researcher path for vulnerability discovery and remediation work that currently gets refused.
- Whether the Bitcoin Red Team publishes a checkable tally of findings and severities rather than a spend figure and a coverage claim.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence28
- Adoption32
- Hype gap+34
- Incentives66
- Confidence44
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Calle said the Bitcoin Red Team formed as an emergency effort to find AI-assisted security threats across the Bitcoin ecosystem, and exists to get ahead of attackers as fast as possible.
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [2]
Calle said Chinese AI models are used far more than U.S. models for the group's security research because American models often block cybersecurity-related requests, adding: "It's not even close."
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [3]
Calle said U.S.-based frontier models are still arguably more intelligent than any other models in the world, but come with heavy guardrailing that limits their use in the cybersecurity realm.
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [4]
Calle said U.S. models sometimes refused to help find vulnerabilities and, in some cases, would not assist with fixing vulnerabilities.
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [5]
Calle warned that AI allows people without advanced security expertise to carry out exploits from beginning to end.
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [6]
In an August 4, 2026 update, Rob Hamilton said the Bitcoin Red Team had been working around the clock with about $20,000 of spend to that point across different services, that funding is secured, and that donations are not necessary.
ReportedSupportedSource: Rob Hamilton, CEO of Bitcoin insurance firm AnchorWatch2 sources— create a free account to open themView cited source - [7]
Calle said the Bitcoin Red Team began taking shape after AnchorWatch CEO Rob Hamilton started examining Bitcoin projects following the Coldcard air-gapped wallet hack.
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [8]
Calle said the arrival of Kimi K3 caused a lot of chaos in the cybersecurity realm because "it gave attackers as well as defenders unprecedented power."
ReportedSupportedSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [9]
In February, Anthropic accused Chinese AI labs DeepSeek, Moonshot AI and MiniMax of using roughly 24,000 fraudulent accounts to extract more than 16 million Claude exchanges through model distillation.
- [10]
The Trump administration warned in April that Chinese entities were conducting similar distillation campaigns on an "industrial scale."
ReportedSupportedSource: Trump administration2 sources— create a free account to open themView cited source - [11]
The group shares its findings with affected developers and uses their feedback to improve its vulnerability classifications and severity ratings.
- [12]
The Bitcoin Red Team consists of about 20 to 25 volunteers, according to Calle, many of whom prefer to remain pseudonymous.
- [13]
Calle is a pseudonymous Bitcoin software developer who helps maintain the open-source protocol Cashu, and told Decrypt: "At this point, it is a question about time."
- [14]
Calle stressed the group has found no issues in the Bitcoin protocol itself; the concern lies with applications, wallets, services and other software built around Bitcoin.
- [15]
Calle said the group acts proactively and has covered almost the entire significant open-source Bitcoin ecosystem with its own sweeps, in addition to receiving inbound scan requests from projects.
ReportedInsufficientSource: Calle, speaking to Decrypt2 sources— create a free account to open themView cited source - [16]
The roughly $20,000 spent to date works out to about $800 to $1,000 per volunteer across a roster of 20 to 25 people.
- [17]
More than 16 million Claude exchanges across roughly 24,000 accounts averages about 667 exchanges per account.
Sources
1 independent publisher whose own reporting we read for this story.
- decrypt.coAI Has Made Bitcoin Software a Target—This Group Is Fighting Back
1 article · August 22, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.