Bitcoin advocates press AI giants for secure access to frontier cyber‑defense tools
A growing alliance of Bitcoin and digital‑asset firms is demanding that the world’s biggest AI companies open their most advanced cybersecurity models to vetted defenders before attackers gain the upper hand.
More than 40 organizations, coordinated by the Bitcoin Policy Institute, have signed an open letter urging leading AI labs to grant qualified open‑source security researchers controlled access to their cutting‑edge systems. The appeal comes amid a rapid escalation in AI‑assisted hacking campaigns targeting crypto companies and financial platforms.
The initiative was unveiled in an August 10 post on X, where the Bitcoin Policy Institute described the coalition as a broad cross‑section of the digital‑asset ecosystem. Signatories include major players such as Block, Coinbase, Strategy, MARA, Galaxy, BitGo, Brink, OpenSats, Chaincode Labs, Spiral, Trezor, Unchained, Btrust, and Fedi.
What the coalition is actually asking AI labs to do
The letter does not demand that powerful cybersecurity‑capable models be made freely available to everyone. Instead, it calls for a structured, tightly controlled program that would:
– Give qualified open‑source defenders early access to frontier cybersecurity models
– Provide enough computing resources to run realistic, large‑scale tests
– Offer secure, sandboxed research environments to prevent model misuse
– Establish direct communication channels between vetted researchers and AI security teams
With those tools, the coalition argues, trusted researchers could systematically probe Bitcoin wallets, payment infrastructure, and related open‑source software for vulnerabilities-ideally identifying and fixing flaws before hostile actors can discover and weaponize them.
The Bitcoin Policy Institute stressed that recent events “have made the need for this abundantly clear,” pointing to a surge in AI‑enabled threat activity and long‑undetected weaknesses inside critical crypto infrastructure.
At the time of writing, none of the leading AI labs had publicly announced a dedicated access program meeting the coalition’s specific criteria.
AI defenses constrained while attackers adapt
One of the coalition’s core arguments is that current safety measures on commercial AI services can unintentionally hinder legitimate security research. While mainstream platforms impose guardrails, usage monitoring, and account‑level enforcement, well‑resourced attackers are increasingly migrating to open or locally hosted models that sit entirely outside these controls.
Criminal groups and state‑linked operators can download powerful models, run them on privately controlled hardware, and use them to write malware, analyze stolen data, generate phishing content, or automate reconnaissance-without triggering the detection systems and content filters that protect typical users.
Security researchers, by contrast, often find themselves blocked or throttled when they try to explore the same attack surfaces through commercial interfaces, even when their work is aimed at strengthening defenses. According to the coalition, this imbalance leaves defenders “fighting with one hand tied behind their back” while adversaries operate with few practical constraints.
North Korea‑linked hackers show how local AI changes the game
The letter points to concrete evidence that sophisticated threat actors have already integrated AI into their cyber operations. One example is Kimsuky, a hacking group linked to North Korea, which is reported to have set up three separate local AI environments based on tools such as Ollama, GPT4All, and Msty.
By running models locally, Kimsuky can:
– Develop and refine malware without exposing samples or prompts to third‑party providers
– Analyze large volumes of data stolen from victims
– Craft highly tailored phishing campaigns that mimic the tone and style of trusted institutions
– Automate components of their attack workflow, from initial contact to post‑exploitation
These AI systems have reportedly been used to generate phishing content focused on cryptocurrency companies, investment firms, and fintech platforms-targets that manage substantial flows of digital assets and sensitive financial information.
Because the models run on infrastructure controlled by the attackers, they are not subject to the monitoring, rate limiting, or content policies that commercial AI services apply. That capability gap is central to the Bitcoin coalition’s case: if malicious actors can freely exploit local frontier‑level tools, limiting responsible defenders’ access to comparable systems does little to enhance real‑world safety.
A national security dimension for the U.S.
Beyond the direct threat to crypto markets, the coalition highlights a broader national security angle. Many of the signatories-such as Coinbase, Strategy, Block, MARA, and Galaxy-are publicly traded or U.S.‑based companies with deep exposure to the Bitcoin and digital‑asset infrastructure on which American consumers and institutions rely.
Successful attacks on wallets, custodial platforms, or Bitcoin‑related infrastructure could:
– Drain funds held by U.S. retail customers
– Disrupt services used by institutional custodians and asset managers
– Undermine confidence in regulated companies that have integrated Bitcoin into their offerings
– Ripple into broader financial markets via publicly listed firms
The software at risk is often maintained by a globally distributed open‑source community, but the economic and political fallout of major incidents would be felt acutely in the United States. That, the coalition suggests, makes access to advanced defensive AI tools not just an industry concern, but a matter of strategic resilience.
Bitcoin’s recent security failures reveal systemic blind spots
The call for frontier‑model access is also rooted in the Bitcoin ecosystem’s own recent experience with security lapses that went unnoticed for long periods.
One high‑profile example involves a firmware build error in certain Coldcard hardware wallets. The flaw reportedly degraded the quality of randomness (entropy) used to generate seed phrases-the foundational secret that protects a user’s Bitcoin holdings.
Weakened entropy meant that an attacker could search a much smaller keyspace when trying to guess or derive wallet keys. In practice, this allowed funds to be drained from affected wallets without the attacker ever needing physical access to the devices.
Research from Galaxy estimated that confirmed losses linked to these attacks amounted to around 1,596 BTC, with a further suspected wave potentially pushing total losses to roughly 2,055 BTC. The underlying error is believed to have persisted since 2021, illustrating how subtle failures can sit undetected in widely used open‑source code for years.
AI‑enhanced analysis later broadened the scope of the investigation, uncovering similar classes of weaknesses in other components across the Bitcoin software stack. Automated scanning and reasoning tools were able to flag patterns that manual reviewers had missed, reinforcing the argument that advanced models can play a powerful role in defensive work.
Another volunteer initiative, informally known as the Bitcoin Red Team, has applied AI‑assisted methods to comb through open‑source Bitcoin applications and infrastructure. The group reported identifying thousands of potential security issues and misconfigurations, underscoring both the scale of the attack surface and the potential value of automated, model‑driven scrutiny.
Why frontier models matter for defenders
The coalition’s emphasis on “frontier” AI models is deliberate. These systems typically offer:
– Stronger code understanding and generation
– Better ability to reason about complex, multi‑step exploits
– Improved performance on tasks like formal verification, fuzzing, and static analysis
– More realistic simulation of attacker behavior and novel exploit paths
In cybersecurity, that translates into new defensive capabilities: models can help prioritize high‑risk bugs, correlate subtle indicators across large codebases, simulate chains of exploits, and even suggest patches in natural language developers can quickly implement.
However, these same strengths also make frontier models dangerous in the wrong hands. The coalition’s proposal is an attempt to resolve that tension by channeling the most capable tools toward structured, accountable defenders rather than leaving them exclusively to private AI labs and unmonitored adversaries.
How a controlled access program could work
Although the open letter sketches the broad contours, much of the real work would lie in designing an access framework that maximizes defensive value while minimizing abuse. A robust program might include:
– Rigorous vetting of participating researchers and organizations
– Clear scoping of what kinds of experiments and testing are permitted
– Logging and auditing of model interactions within secure environments
– Collaboration with affected open‑source projects to handle disclosure and patching
– Time‑boxed early access windows before upgraded models are deployed more widely
For Bitcoin infrastructure, this could mean standing “red‑team seasons” where frontier models are turned inward on wallet software, protocol implementations, payment processors, and custody systems. Findings would be coordinated with maintainers under responsible disclosure principles, giving them a head start on fixes before vulnerabilities are exploited at scale.
Potential concerns from AI labs
AI developers may hesitate to open direct access to their most advanced systems, even for defenders. Their concerns might include:
– The risk that powerful capabilities leak outside the controlled program
– Legal and regulatory exposure if a model is misused by an approved participant
– The cost of providing compute and security infrastructure at meaningful scale
– Uncertainty about how to evaluate which organizations are “trusted”
The Bitcoin coalition’s proposal implicitly acknowledges these tensions by avoiding calls for full public release. Instead, it frames the access program as a partnership: AI labs would gain feedback on how their models behave in real‑world security contexts, while defenders would gain tools they currently lack.
In practice, AI labs might start with a small pilot program focused on a narrow set of high‑value targets-such as widely used Bitcoin wallet software-and gradually expand participation as governance and auditing mechanisms prove themselves.
What happens if AI labs say no?
If AI companies decline to provide this kind of controlled access, the security gap that worries Bitcoin organizations may widen. In that scenario, defenders would likely lean more heavily on:
– Less‑capable open models they can run locally
– Traditional static and dynamic analysis tools
– Manual code review and peer auditing
– Grassroots initiatives like volunteer red‑teams
While these efforts can still uncover critical issues, they may struggle to match the pace and sophistication of attackers using newer, more capable systems. Over time, that asymmetry could manifest as more frequent breaches, larger thefts, and deeper erosion of trust in digital‑asset infrastructure.
The coalition’s message is that the choice is not between “safe” and “unsafe” models, but between a world where only adversaries have unconstrained access and one where responsible defenders are equipped to keep up.
A test case for AI governance and open‑source security
Bitcoin, with its transparent codebase and high economic stakes, is emerging as an early testbed for how AI, security, and open‑source governance will intersect. The outcome of this push for frontier‑model access may set precedents far beyond crypto:
– Other critical open‑source projects, from core internet infrastructure to industrial control software, face similar challenges.
– Regulators are starting to ask how AI can be used both to secure and to attack financial and digital systems.
– AI companies are under pressure to demonstrate that their safety strategies genuinely reduce risk rather than simply restricting responsible researchers.
For now, the coalition’s stance is clear: powerful AI is already part of the threat landscape. The question is whether it will also be systematically integrated into the defensive playbook-starting with Bitcoin’s vast and still‑evolving ecosystem.

