Kimi K3 outperforms rival open-weight models in finding Bitcoin vulnerabilities

1 hour ago 1



A volunteer group called the Bitcoin Red Team just ran one of the most ambitious automated security audits the crypto ecosystem has ever seen. Their weapon of choice: Kimi K3, an open-weight AI model built by China’s Moonshot AI. Over roughly 108 hours, the model catalogued 7,958 potential security findings across 501 Bitcoin-related open-source projects, with 1,280 of those rated high or critical severity. Kimi K3 outperformed every other open-weight model tested, including Zhipu’s GLM-5.2, in standardized vulnerability detection benchmarks. What the audit actually found Of the 7,958 potential issues flagged by Kimi K3, only 24.7% could be dynamically reproduced. At the time of reporting, 29.4% of the findings had been communicated upstream to the affected projects. The most consequential discovery was a critical two-factor authentication bypass in BTCPay Server version 2.4.2. The vulnerability had already been exploited to extract Lightning wallet credentials before it was patched, making it a live, in-the-wild security incident rather than a theoretical concern. How Kimi K3 stacks up The UK’s AI Safety Institute and its counterpart CAISI ran a preliminary assessment of Kimi K3 i...

Read Entire Article