I think he means to say "we're using open weight models, and they're finding a lot" which is true.
Closed models are *very* good at finding *subtle* issues that are missed by some models.
It's a jagged frontier, so there's value in throwing many approaches at the issue.
When the dust settles, we'll have to talk about the fact that not a single vulnerability was found by a US frontier model.
Instead, we're spending $10k a day on open weights models like Kimi K3 and Qwen 3.8 to find vulnerabilities in Bitcoin infrastructure.
It's a disaster.