Kimi K3 Uncovers 5,000 Security Vulnerabilities in a Day: Is the Bitcoin Ecosystem’s Security at Risk?
Original translation: AididiaoJP, Foresight News
Bitcoin and 加密 traders are still reeling from a massive attack worth approximately $100 million, which briefly ignited fears of another round of price crashes.
Since news of the hardware wallet Coldcard breach first broke, Bitcoin’s price has bounced back somewhat but remains near recent lows. Traders are generally on edge, bracing for another sharp shock.
Against this backdrop, Bitcoin developers using 人工智能 tools have uncovered nearly 5,000 security vulnerabilities across close to 400 projects in just 24 hours. The situation has been described bluntly as “extremely bad.”
A volunteer team of Bitcoin developers is conducting a large-scale, coordinated security audit. They have already confirmed that the overall state of ecosystem security is “extremely bad.”
Within 24 hours, they scanned approximately 390 Bitcoin-related projects and identified a total of 4,962 security vulnerabilities, including 85 critical-level flaws and 635 high-risk ones. The vast majority of these vulnerabilities have already been verified by project teams.
“We’ve grown to 16 people, globally distributed, working around the clock in shifts,” wrote Calle, the anonymous developer of the Cashu ecash protocol, on X. “We are conducting a large-scale ecosystem security audit of the Bitcoin codebase.”
The audit team is using Moonshot’s Kimi K3 model—an open-weight AI tool from China. Calle revealed that the team spends approximately $10,000 per day on computing power, with costs covered by OpenSats.
“We’ve been working around the clock,” said Rob Hamilton, CEO of Bitcoin insurance company AnchorWatch and a member of the audit team, also on X, noting that the team has already uncovered some “critical issues.”
The efficiency of this audit has been astonishing. One developer noted that, on average, a critical vulnerability has been uncovered roughly every hour. AI is simultaneously accelerating both defenders and attackers—a dynamic already hinted at in the recent Coldcard incident.
Over the past year, Bitcoin’s price has already pulled back significantly, leaving the market highly sensitive to further downside. The sudden outbreak of hardware wallet security incidents has thrust the question of “is self-custody really safe” back into the spotlight.
Last week, the Coldcard Bitcoin hardware wallet suffered an exploit, with nearly 2,000 BTC (worth just over $100 million) drained from more than 5,200 addresses in a matter of days. The attackers exploited a key-generation flaw that had existed for five years.
The Coldcard team has urgently called on users to move their funds and repeatedly begged people on social media to “help spread the word.”
“Please treat this as an emergency,” the official Coldcard account wrote. “Migrate your funds immediately. Follow the recommendations for your device model, upgrade the device, generate a new seed, and carefully transfer your funds… The threat is ongoing.”
A wallet address linked to the hackers still holds approximately $36 million in Bitcoin, the vast majority believed to be stolen funds. Since the incident came to light, multiple transfers have flowed into the address, some carrying messages via Bitcoin’s OP_RETURN function.
One message read: “I wash BTC, do KYC and cash out. I take 10%.” This has been interpreted as a money-laundering pitch attempting to recruit the hackers as clients. More messages were direct pleas for the return of the stolen Bitcoin.
Some on-chain analysts have pointed out that with the vulnerability now public, attention at a peak, and cutting-edge large language models accessible to nearly everyone, multiple hacker teams may already be simultaneously researching how to expand their gains. “You’re racing against the clock.”
Another anonymous co-owner of Bitcoin.org, Cobra, said bluntly that he has a “very bad feeling”—AI may well have already played a role in the draining of Coldcard funds.
This AI-driven vulnerability scan, combined with the earlier large-scale Coldcard theft, is pushing Bitcoin ecosystem security to a new tipping point. Developers are using AI to accelerate vulnerability discovery, while attackers may be using the same tools to accelerate exploitation. The window left for fixes and migration is being compressed.
For now, Bitcoin’s price continues to fluctuate at low levels, with traders awaiting the next potential shock. And this audit, burning through $10,000 in computing power per day, may only be the beginning of a broader security review.
In this round, over 355 million JST tokens were burned, accounting for 3.59% of the total token supply, with the corresponding burn value surpassing $34.59 million. This set a new single-round record for the scale of funds burned, significantly exceeding the community’s general expectations. The key to this repurchase and burn achieving such strong momentum lies in the superposition of two major initiatives. In addition to the regular quarterly repurchase and burn plan for Q2 2026, a dedicated burn of historical USDJ stability fees was conducted independently. The combined funds from these two parts propelled the actual scale of burned funds in this round to new heights, notably exceeding market estimates and releasing ecosystem benefits far beyond expectations for global JST holders. It is important to emphasize that all funds…






