News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

mediumBitcoin / FOSScustody

Bitcoin Red Team: ~8k AI-assisted findings across 501 FOSS projects

Volunteer Bitcoin Red Team (post–Coldcard) reports scanning ~501 open-source Bitcoin projects and filing ~7,958 security findings, with ~1,280 rated high or critical — numbers from team lead Calle’s campaign update (≈108 hours in), with earlier Bitcoin Magazine coverage of the first sprint (~390 repos / ~4,962 findings / 85 critical). OpenSats funds AI compute (tens of thousands of dollars); Kimi K3 has taken the majority of inference spend after early limits on some US lab models, with other models also used. CoinBureau’s “Kimi scanned nearly all of Bitcoin” framing is overstated: this is a human+AI campaign, findings are not all confirmed exploits, and only a minority had been reported upstream at last update. Maintainers are validating severity; patching is ongoing, not finished.

369 take: AI can flood a repo with “findings”; only maintainer-validated, reproducible issues matter for your bag. After Coldcard, the healthy response is more FOSS red-teaming — not panic that “China’s AI cracked Bitcoin.” Pulse lesson: treat viral AI-audit headlines as Verify-first; keep seed/RNG and wallet-library hygiene in the same bucket as protocol bugs.