According to open-source developer calle, a massive audit powered by the Kimi k3 AI model uncovered widespread issues in legacy repositories. Security researchers completed a rapid scan of virtually all open-source software in the Bitcoin ecosystem and reported the findings directly to project maintainers.
By the numbers
During the first 108 hours of operation, researchers filed 7,958 vulnerabilities across 501 out of 502 reviewed projects.
Out of the total findings, 168 were rated critical and 1,120 high severity. Combined, these high-risk flaws totaled 1,288, representing 16.2% of all bugs found, or an average of 2.57 severe issues per project.
The team has already notified maintainers across 174 projects. Dynamic test runs successfully reproduced 24.7% of the reported bugs, while 74% of the intake arrived via automated scans.
Researchers noted that open-source software is suffering from the fallout of "decades of human slop." They urged engineers to ditch C immediately, citing its inherent memory-safety risks.
The Lightning Network infrastructure also raised serious red flags, with researchers reporting a higher-than-average flaw rate across its protocols.
"We’re experiencing a massive collision between decades of human open source slop against two weeks of Kimi k3. Everything is broken, Bitcoin is burning, but BTC is becoming stronger through this," calle noted.
The AI pipeline
Calle added that projects that integrated AI audits months ago are sitting in a completely different tier. Moving forward, dev teams must build their own internal AI scanning pipelines to keep up with the sheer volume of vulnerabilities.
For abandoned or unmaintained repositories, the team recommends assuming they are completely broken and rewriting them from scratch.
While fix response times vary wildly across teams, exposing the actual health of each project, calle emphasized the strict need for responsible disclosure.
"If you don’t disclose responsibly, boast on Twitter about your findings, or make indications about particular findings, you’ve disqualified yourself as a serious security researcher. Trust is the most important factor in this game. If you lose it, it’s very hard to win back," the developer stressed.
This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.
