Kimi K3, an open-weight AI model from Moonshot AI, identified 7,958 potential security issues across 501 Bitcoin-related open-source projects in just 108 hours, including 1,280 rated as high or critical severity. Among these findings, a critical two-factor authentication bypass in BTCPay Server version 2.4.2 had already been exploited to steal Lightning wallet credentials before being patched. Kimi K3 scored 32% on ExploitBench, outperforming Zhipu’s GLM-5.2 model (24%), but remaining far behind US models from OpenAI and Anthropic (76% on average). The audit effort was triggered by the theft of approximately 594 BTC (estimated at $38 million) due to a flaw in the Coldcard Mk3 firmware in July 2026.
Source: Read the original article

