Raleigh News Today

collapse
Home / Daily News Analysis / Bitcoin firms ask AI labs for same tools attackers already have

Bitcoin firms ask AI labs for same tools attackers already have

Aug 18, 2026  Twila Rosenbaum  4 views
Bitcoin firms ask AI labs for same tools attackers already have

More than three dozen bitcoin and cryptocurrency companies are pressing leading artificial intelligence laboratories to share their most advanced models with open-source security researchers, arguing that current safety restrictions are hindering legitimate defenders while leaving attackers free to exploit the same technology.

The letter, organized by the Bitcoin Policy Institute, was signed by prominent industry players including Coinbase, Block, BitGo, and ARK Invest. It calls on AI labs such as OpenAI, Anthropic, and Google DeepMind to provide earlier access to frontier models, dedicated compute resources, secure testing environments, and direct communication channels with lab security teams. The signatories argue that without these tools, open-source developers working on Bitcoin and related protocols are fighting with one hand tied behind their backs.

The Core Complaint

At the heart of the letter is a stark asymmetry. Malicious actors, the authors write, can freely use publicly available AI models to search for vulnerabilities in Bitcoin-related software, craft exploits, and automate attacks. Meanwhile, security researchers who are trying to defend the same systems often face rate limits, safety filters, and outright denial of service when they attempt to use these models for legitimate vulnerability research.

The problem is especially acute for Bitcoin Core developers. Bitcoin Core is the reference implementation of the Bitcoin protocol, and its security is paramount to the entire ecosystem. Yet, according to the letter, many of these developers find themselves locked out of trusted-partner programs that AI labs have established for vetted security professionals. Even when they are able to access public models, safety guardrails designed to prevent misuse can misinterpret their queries as malicious and block them from completing tasks such as analyzing C++ code for memory safety issues or generating exploit proof-of-concepts for testing.

“Defenders are using weaker tools than attackers,” the letter states. “This is not a hypothetical concern; it is a practical imbalance that is making bitcoin and the broader digital asset ecosystem less secure.”

Real-World Incidents

The signatories point to a series of recent incidents that illustrate the stakes. One notable example is the discovery of vulnerabilities in BTCPay Server and Lightning Network nodes by an AI-powered volunteer initiative known as the “Bitcoin Red Team.” This group of security researchers used publicly available AI models to systematically audit Bitcoin-related open-source projects. Their findings included several high-severity bugs that could, in theory, have been exploited to steal funds or disrupt network operations.

While the Bitcoin Red Team’s work was successful, it was also a struggle. The researchers reported that they had to work around aggressive safety filters, manually reformatting prompts and using indirect language to avoid triggering automated moderation. The process was time-consuming and inefficient, and the team fears that many vulnerabilities remain undiscovered simply because the tools are stacked against them.

Another incident that looms large is the recent Coldcard hardware wallet hack, which went unnoticed for years and ultimately led to the theft of approximately $100 million in user funds. The vulnerability was not found by AI, but post-mortem analyses suggested that AI-assisted code review could have flagged the dangerous pattern much earlier. For the signatories, this is further evidence that AI will play a decisive role in the future of cryptocurrency security, and open-source researchers need to be equipped with the same capabilities as their adversaries.

The Scope of the Request

The letter outlines a concrete set of demands. First, the signatories ask AI labs to include independent open-source security researchers in their trusted-partner and early-access programs. These programs typically provide selected researchers with relaxed safety restrictions and priority access to new models. Currently, participation is often limited to researchers affiliated with large defense contractors, government agencies, or well-funded commercial security firms. The Bitcoin community, which is overwhelmingly open-source and globally distributed, is largely excluded.

Second, the letter requests dedicated compute resources for vulnerability research. Running sophisticated AI-powered fuzzing, static analysis, and code review requires significant processing power, which many volunteer researchers cannot afford. The signatories suggest that AI labs could set aside a portion of their compute capacity for these efforts, perhaps through a grant program or a public-interest partnership.

Third, the letter calls for the creation of secure testing environments. When researchers find a potential vulnerability, they need to be able to test exploit scenarios without causing harm to live networks. AI labs already maintain sandboxed environments for their own security teams, and the letter argues that extending similar capabilities to external researchers would accelerate the discovery and remediation of bugs.

Finally, the signatories request direct communication channels with AI lab security teams. Currently, researchers who encounter safety issues while using AI models often have nowhere to turn. They are left to interact with generic customer support or automated moderation queues, which are slow and unhelpful for complex security-related queries. A direct line to a human security engineer would allow researchers to explain their use case and receive clear guidance on how to proceed.

Industry Support and Broader Context

The letter has gained widespread support across the digital asset industry. In addition to the primary signatories, dozens of other companies and projects have added their names, including exchanges, wallet providers, and infrastructure firms. ARK Invest, a major investment manager known for its focus on disruptive technology, added its voice to the call, signaling that the issue is not just technical but also economic.

Kraken’s parent company, Payward, recently joined Anthropic’s Project Glasswing, an initiative aimed at using AI to identify security vulnerabilities in critical infrastructure. That move suggests that at least some AI labs are beginning to recognize the importance of collaboration with cryptocurrency firms. However, the Bitcoin Policy Institute argues that such partnerships remain the exception rather than the rule.

The broader context is a rapidly evolving landscape where AI is transforming cybersecurity. Large language models have demonstrated remarkable capabilities in code analysis, vulnerability detection, and even exploit generation. At the same time, they can be extremely dangerous in the wrong hands. AI labs have responded by implementing strong safety measures, which are intended to prevent misuse. But those measures are blunt instruments, and they often thwart legitimate research as well.

Bitcoin and other decentralized systems are uniquely dependent on open-source development and peer review. Unlike commercial software, which can rely on in-house security teams, Bitcoin’s security emerges from a global network of volunteer contributors, auditors, and researchers. If these contributors are denied access to cutting-edge AI tools, the entire ecosystem will be at risk.

The signatories emphasize that they are not asking for unrestricted access to dangerous capabilities. They recognize the need for safety and alignment. What they want is a more nuanced, transparent, and inclusive system that can distinguish between malicious actors and bona fide security researchers. They note that AI labs already have the technical means to implement such distinctions, including usage monitoring, behavioral analysis, and controlled execution environments.

The letter also highlights a growing concern about the centralization of AI safety. While AI labs are understandably focused on preventing catastrophic misuse, their current policies often have the unintended consequence of entrenching the power of large, well-connected organizations. By giving preferential treatment to established security firms and government agencies, they are effectively building a security clearinghouse that excludes the very communities that have made cryptocurrency resilient over the past decade.

A Call for Action

The Bitcoin Policy Institute does not expect immediate change, but the letter is designed to start a conversation. It offers a set of practical recommendations that AI labs can adopt without compromising their safety principles. These include open-sourcing safety classifiers, creating formal protocols for security researchers to request exemptions, and supporting independent research initiatives like the Bitcoin Red Team.

In the short term, the gap between attacker and defender capabilities will likely continue to widen. As AI models become more powerful and accessible, malicious actors will find new ways to exploit them. The only effective countermeasure is to ensure that the people who protect Bitcoin and other critical systems have access to the same technology. The letter is a clear and urgent request to AI labs: do not leave open-source defenders behind.

For the bitcoin community, this is more than a matter of convenience; it is fundamental to maintaining the security and decentralization that make digital assets valuable. As one signatory put it, “If we want AI to be a net positive for humanity, we need to make sure it is not used to destroy the core infrastructure of the digital economy. The people trying to protect that infrastructure need the best available tools, not the weakest ones.”

The AI labs, for their part, have shown some willingness to engage. Anthropic and OpenAI have both funded external security research and participated in bug bounty programs. But the scope of these efforts remains limited. The letter asks for a more systematic and sustained commitment, one that treats open-source security researchers as first-class partners rather than potential threats.

As the debate over AI safety continues, the funding and resource disparities between large corporations and independent researchers will become increasingly significant. The Bitcoin Policy Institute’s letter is one of the first coordinated efforts from the cryptocurrency industry to address this imbalance. It remains to be seen whether AI labs will respond with concrete policy changes, but the message is clear: the tools of offense and defense must be developed and distributed in equal measure.


Source: Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy