Kimi K3 Security Audit Uncovers Over 7,900 Potential Vulnerabilities Across Bitcoin Projects
A recent automated security audit of Bitcoin-related open-source projects used Kimi K3, an open-weight AI model developed by China's Moonshot AI. The Red Team, a volunteer group, ran the audit over approximately 108 hours and identified 7,958 potential security findings across 501 projects.
Kimi K3 outperformed other open-weight models in detecting vulnerabilities, including Zhipu's GLM-5.2, in standardized benchmarks. Of the flagged issues, only 24.7% could be dynamically reproduced, with 29.4% having been communicated to the affected projects at the time of reporting.
The most significant discovery was a critical two-factor authentication bypass in BTCPay Server version 2.4.2, which had already been exploited to extract Lightning wallet credentials before being patched.