Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

By: Juan Galt
13 August 2026 at 12:18

Bitcoin Magazine

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

Bitcoin company leaders and open-source developers are publicly stating that Chinese AI models are currently outperforming restricted American frontier systems in defensive cybersecurity work, forcing researchers to rely on them to secure critical Bitcoin infrastructure.

Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance company, reported cripling American AI restrictions. After integrating OpenAI’s trusted cyber program (having already completed KYC months earlier), he was blocked from further analysis on a codebase he had already responsibly disclosed. “It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure,” Hamilton wrote. “Black hats will not hit these issues. The white hats will.” Days later, he gained access to OpenAI’s “Daybreak Blue” cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.

Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation bluntly. “I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin,” he posted. “USA AI industry is completely cooked if they don’t change this path,” he concluded, adding “Open-source Chinese LLMs. [orange heart emoji],” meaning that open Chinese models like Kimi K3 are actually helpful to Bitcoin. In a follow-up, Pouliot detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked the American models he pays for to review the same patch, they refused.

PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, publicly highlighted the performance gap. “US-based Frontier AI Model – ‘You’re absolutely right!’ Chinese Open Model – ‘78 critical vulnerabilities found.’ The implications of this are unfathomable,” he posted. In a follow-up, he added that he felt he was “basically asking Xi to not get my software hacked at this point,” calling for OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.

Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter demanding trusted access to frontier models for open-source defenders. “Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks,” he wrote. “RED TEAM NEEDS THE MODELS.”

On August 10, the Bitcoin Policy Institute — a Bitcoin and, of late, AI-focused policy think tank — published an open letter signed by more than 70 organizations across the digital-asset ecosystem, including major custodians, exchanges, mining firms, and open-source development groups. The letter calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code, and direct channels with lab security teams, stating that frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.

These statements reflect a broad pattern among Bitcoin security researchers: American models from OpenAI and Anthropic frequently refuse or restrict legitimate defensive work, even to users who are supposed to have been granted explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results. Concerns about hosting infrastructure of Chinese models being an attack vector can also be mitigated, since they are open source and can be run on American-hosted data centers, a trend that is likely to threaten the U.S. AI market if it continues.

Coldcard Exploit Triggers Ecosystem-Wide Response

The cybersecurity pressure became acute in the Bitcoin industry after a firmware flaw in Coldcard hardware wallets was exploited beginning July 30, resulting in the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine published an urgent advisory urging affected users to migrate funds: COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED.

In response, a volunteer effort known as the Bitcoin Red Team formed, led by open-source developer Calle (creator of Cashu and the Android version of Bitchat) and Rob Hamilton. The group has conducted large-scale AI-assisted audits of Bitcoin open-source repositories, using models including Kimi K3 as the primary workhorse alongside limited access to Western systems. Early results, covered by Bitcoin Magazine, showed thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.

By August 8, after more than 100 hours of work involving dozens of contributors, the team reported scanning 501 projects and producing 7,958 findings, of which 1,280 were rated high or critical severity. The majority of compute spend continued to go to Chinese open-weight models.

Lessons from the Red Team Campaign

Most recently, Calle shared lessons from the intensive red-team period. The effort has essentially completed a basic scan of virtually the entire Bitcoin open-source landscape; low-hanging fruit is largely exhausted, the developer wrote on this X account. Maintainers across projects have validated many of the critical and high-severity reports, while response times from projects vary widely and serve as a signal of overall health.

Key takeaways include the need for every project to maintain its own permanent AI audit pipeline going forward. Projects that began such reviews months earlier are in a markedly stronger position. Unmaintained repositories should be treated as likely broken and unreliable. 

Calle also warned that the human-only era of open-source security review is over; verification is now effectively free, and information overload must be handled with AI rather than complaints about PR slop. Multiple concurrent and diverse human approaches remain the strongest method for finding vulnerabilities, and external red-teaming will likely be required indefinitely. 

Calle also repeatedly emphasized that developers should stop writing security-critical code in C. In a follow-up post he explained: “we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.”

Bitcoin was the first major open-source ecosystem to confront this collision between accumulated human code and frontier AI capability. The rest of the software world is expected to follow.

This post Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit

By: Juan Galt
5 August 2026 at 16:33

Bitcoin Magazine

Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit

Rallied by the recent, catastrophic vulnerability in Coldcard hardware wallets, exploited to the tune of over $100 million, the Bitcoin community has rallied to prevent future critical bugs in the industry’s open source software.

PSA: Any users of Coldcard wallets that have not migrated their bitcoin to new seeds generated in secure firmware are still at risk. It may not be too late to act; see advisory on the matter. 


Led by Calle, software engineer, avid vibe coder and creator of the Android version of Bitchat, and Rob Hamilton, the CEO of Anchorwatch a Bitcoin self-custody insurance company, the Bitcoin Red Team has now secured funding, with over $40,000 spent in AI tokens to audit over 390 Open Source repositories across Bitcoin. 

Colloquially called the “Bitcoin Red Team”, with memes about Rob Hamilton and Calle now being the CEO and CTO of Bitcoin, this AI-driven security audit is having a serious impact across the industry. Just a few days ago, buried in the news of ongoing thefts of bitcoin from MK3+ Coldcards due to an RNG bug, Boltz exchange announced it would be pausing operations to catch up with AI-driven hacking attempts. 

“27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour,” said Calle in the most recent update on Red Team efforts to shore up the industry’s cybersecurity.

The Red Team security review effort is using models like Kimi K3, GPT Sol, Fable, Opus and GLM5.2, some of the most expensive and cutting-edge models in the market. At first, access to OpenAI and Anthropic models was limited, leading to an over-reliance on Chinese open-source models, a fact which many in the industry lamented and saw as a bad omen for U.S. AI dominance. But as the Red Team project grew in influence since last week’s Coldcard hack, connections have been established and confirmed with OpenAI, giving Red Team access to GPT Sol. Hamilton’s mention of Fable in his August 4 tweet suggests access to Anthropic has also been established.

Expenses which were last tallied at over $40,000 have been covered by OpenSats, a non profit 501c3 organization dedicated to funding open source Bitcoin development projects. The Bitcoin Red Team does not currently have a website or a GitHub repository to link to, but the team is made up of many individuals within the Bitcoin industry. Individuals publicly thanked for their support include but are not limited to danielabrozzoni, lylepratt, stutxo, benthecarman, thesimplekid

Hamilton shared that a custom harness has been built and is evolving quickly. Made up at one point of 171,599 lines of code, the harness is designed to identify and test critical Bitcoin software libraries and high-load-bearing code, identify and document vulnerabilities, reproduce them and package the proven data into useful reports. Ultimately delivering the information responsibly to engineers in the industry. Hamilton also shared that Red Team intends to open source the harness such that Bitcoin companies can run it against their closed-source code. 

Red Team is actively reaching out to relevant open source projects with critical vulnerabilities discovered, leading to a broad sense of dread from engineers in the industry when they receive cold direct messages from Hamilton or Calle, as seen in various humorous screenshots shared on social media.

https://x.com/callebtc/status/2085035257477190080 

Among the key insights shared by Red Team publicly as this AI-driven security update of Bitcoin FOSS takes place, Hamilton shared that engineers with specific subject matter could sometimes yield high-value results from the Harness, which might otherwise “smell out something is wrong,” but might be missing niche context. An insight which speaks to the importance of having human intelligence and experience work hand in hand with the AI to efficiently identify critical vulnerabilities.

Hamilton also ended a multi-day Red Team effort after the Coldcard hack with some personal notes. He said that the discovered vulnerability in Coldcard random number generators and consequent exploitation of the bug by hackers had been a “spiritual attack” on Bitcoin and the self-custody ethos of the industry, “I mean that in the literal sense of the words”. After expressing grief for the losses experienced by many Bitcoiners during this now historic hack, Hamilton closed his tweet with a tone of hardened resolution:

“While things are not easy right now. I have the highest conviction ever in my life that the idea and technology of Bitcoin is worth fighting for. To that end. There is no Bitcoin without self-custody. This is non-negotiable.”

This post Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions

By: Juan Galt
30 July 2026 at 10:00

Bitcoin Magazine

Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions

Bitchat, Jack Dorsey’s censorship-resistant, Bluetooth-enabled messaging app, has gone viral again, this time due to the Indian Government trying to get it banned from GitHub. In this latest round of authoritarian measures versus decentralized technologies, Bitchat has won. 

In July 2025, Jack Dorsey announced a new messaging application he described as a weekend project. The app, called Bitchat, was designed to work without internet access, phone numbers, user accounts, or central servers. It relied instead on Bluetooth mesh networks for local communication and the Nostr protocol for wider reach.

A year later, that same application became the subject of a formal takedown request from India’s cybercrime authorities during a period of student protests. The episode offers a clear illustration of how cypherpunk ideas—building systems that function without permission from intermediaries—continue to shape tools used in moments of political tension.

Calle, one of the main developers behind the Android version of the app, took the statements from the Indian government as a positive review of Bitchat’s effectiveness, tweeting:

“India forces GitHub to take down Bitchat

‘Bitchat enables anonymous communication without mandatory user registration, phone number verification, or centralized logging of communications. 

The technical architecture of the application significantly impedes interception, attribution, and investigation by law enforcement agencies.’ – Government of India”

What Bitchat Is

Bitchat is a peer-to-peer encrypted messaging application. Devices form local mesh networks over Bluetooth, automatically discovering nearby peers and relaying messages across multiple hops. When internet connectivity is available, the app can fall back to Nostr relays. Users can join public local channels, send private end-to-end encrypted messages, and access location-based channels organized by geographic zones.

The application requires no registration and includes a panic feature that clears stored data. The code is open source, with the primary repositories hosted under the permissionlesstech organization on GitHub. The iOS version is available on the App Store; the Android version is on Google Play and distributed via GitHub releases, as well as many other app stores like Nostr’s Zapstore. Recent updates added the ability for Android devices to share the installation file directly with nearby phones over Wi-Fi or Nearby Share, letting new users join the mesh easily without the need for internet access.

Key figures associated with the project include Jack Dorsey and open-source developer Calle, known for work on Cashu ecash. Bitcoin Magazine has previously noted experimental demonstrations of offline Bitcoin-related payments moving across the same mesh. 

Earlier Deployments

Bitchat first saw significant real-world use during periods of government-restricted connectivity. In September 2025, during unrest in Nepal, the app recorded nearly 50,000 downloads from that country in a single day, according to data shared by Calle and reported by Bitcoin Magazine. Similar spikes occurred during blackouts in other regions. In January 2026, Iranian users turned to Bitchat and a localized fork during internet restrictions, as covered in Bitcoin Magazine.

These earlier cases established a pattern: when conventional mobile networks or social platforms become unreliable or restricted, tools that operate independently of those networks see rapid adoption.

The India Events

In May 2026, India’s National Eligibility Entrance Test (NEET-UG) for medical school admissions was canceled after evidence of a significant leak of the test’s questions. The controversy, involving millions of candidates, undermined the fairness of the exam and was linked to student suicides, contributing to the growth of a youth-led satirical movement known as the Cockroach Janta Party (CJP). Protests centered on demands for accountability from Education Minister Dharmendra Pradhan and broader reforms to the examination system.

By mid-July, demonstrators had gathered at Jantar Mantar in New Delhi and attempted marches toward Parliament. Reports indicated blackouts on mobile data or internet access in areas around the protests. On 24 July 2026, the Indian Cybercrime Coordination Centre (I4C), issued a notice directing GitHub to restrict access to three Bitchat repositories within three hours. The notice cited the application’s ability to function during network restrictions and internet shutdowns, arguing that this architecture could impede lawful interception and attribution.

On 24 July, Dorsey posted the notice on X with the statement: “the government of India does not like technologies like bitchat and wants it taken down.” Market data from Sensor Tower, according to TechCrunch, reported across multiple outlets, showed that India accounted for approximately 85 percent of the app’s global downloads between 17 and 23 July, with more than 91,000 downloads in India over five days and daily active users exceeding 330,000 at the peak.

The GitHub repositories remained accessible in the immediate aftermath, despite the takedown attempt by the Indian government. Developers and users circulated mirrors, including on decentralized platforms such as Radicle. The application itself continued to function on devices that already had it installed, and the offline file-sharing feature reduced reliance on app stores or GitHub for further distribution. Pradhan resigned on 25 July.

Historical Context

The use of messaging tools during protests is not new, nor is Dorsey’s role in support of technologies useful during tense democratic protests. During the Arab Spring, platforms such as Twitter and Facebook were widely credited with helping coordinate demonstrations and amplify information, leading some observers to describe the events as “Twitter revolutions” or “Facebook revolutions.” Those centralized services, however, remained dependent on internet access and corporate intermediaries that could be pressured or blocked and in some cases were.

A closer technological predecessor appeared in 2014 during Hong Kong’s Umbrella Movement. Protesters downloaded FireChat, a mesh-networking application that allowed devices to communicate directly over Bluetooth or Wi-Fi without internet. The app saw hundreds of thousands of downloads and millions of chat sessions in a short period as mobile networks became congested or as users prepared for possible disruptions.

Bitchat continues this line of development, though more closely integrated with Bitcoin-associated technologies. It combines mesh networking with an open protocol (Nostr), stronger cryptographic defaults, and fully open-source code. The response to the Indian GitHub notice, which saw rapid mirroring and peer-to-peer distribution of the application itself, illustrates a further step: the tool is no longer dependent on a single company or platform for its survival; once it has been distributed, it self-replicates.

Cypherpunk Principles in Practice

In 1993, Eric Hughes published A Cypherpunk’s Manifesto. It opens with the statement: “Privacy is necessary for an open society in the electronic age.” The manifesto argues that individuals cannot rely on governments or corporations to protect privacy and that the practical response is to write and deploy code that makes surveillance and control more difficult.

Bitchat is an application of that approach to communication. It does not require user information to function; identities are purely based on cryptography. Users do not need to trust a central operator. It continues to function when conventional infrastructure is restricted. When an intermediary such as GitHub is asked to remove the source code, the popularity and the offline distribution methods of the project limited the effectiveness of the request.

This does not make the technology inherently aligned with any particular political outcome, but this is now the third time it goes viral in the context of democratic demonstrations as a solution to government-driven internet censorship. From FireChat in Hong Kong to Bitchat in Nepal, Iran, and now India, the same underlying demand appears: communication that does not disappear when the network does.  Bitchat servers that demand by giving people tools to communicate and coordinate without centralized infrastructure.

This post Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions first appeared on Bitcoin Magazine and is written by Juan Galt.

❌
❌