Bitcoin Red Team said it expanded its AI-assisted review of Bitcoin-related open-source software to 501 projects, logging 7,958 findings after 108 hours of work. The group said 1,280 findings were classified as high or critical, while 24.7% had been dynamically reproduced and 29.4% had been reported upstream to maintainers at that point, underscoring that the tally does not represent confirmed exploitable vulnerabilities. The latest results extend an earlier sweep of 390 projects that surfaced 4,962 potential issues, including 720 then classified as high or critical. Calle, a pseudonymous developer involved in the effort, said the team has now completed a basic scan of almost the entire Bitcoin open-source ecosystem and that much of the easier-to-find vulnerability surface has already been examined. He described Kimi K3, a model from Moonshot AI, as the campaign's main AI tool, arguing that newer models can review years of accumulated open-source code at far greater speed than human researchers alone. Independent testing cited in the update suggested Kimi K3 has meaningful cybersecurity capability, though it still trails the strongest U.S. closed models. The campaign has already produced concrete fixes. BTCPay Server credited Bitcoin Red Team researchers Bruno Garcia and Ben Carman with reporting a critical vulnerability that was already being exploited, and version 2.4.2 fixed a two-factor authentication bypass affecting Greenfield Basic Authentication. BTCPay later said attackers had obtained LND admin macaroon credentials from affected installations and used them to access connected Lightning wallets, and on Aug. 14 the project released another security-focused candidate, v2.4.3-rc4, to address additional reported vulnerabilities. The broader takeaway is that AI-assisted discovery can scale rapidly, but validation, disclosure and patching remain the slower, decisive stages for wallets, Lightning infrastructure, payment software and other Bitcoin-related tools.