🔥BTC/USDT

Crypto firms ask AI labs for Bitcoin security access

A coalition of cryptocurrency companies, hardware wallet makers and nonprofit groups is urging leading artificial intelligence laboratories to give vetted open-source security teams early access to their most capable models, arguing that Bitcoin and other critical financial software could otherwise face a growing imbalance against AI-enabled attackers.

The request, published Monday in a letter coordinated by the Bitcoin Policy Institute, asks frontier AI developers to create or expand standing “trusted-access” programs for qualified defenders. The intended users include Bitcoin Core contributors and maintainers of open-source tools used across digital asset custody, payments and infrastructure.

The group’s argument centers on access rather than a call to weaken AI safety controls. It says cybersecurity programs at major labs can be difficult for open-source maintainers to enter, while restrictions on public-facing systems may limit legitimate security research. Those barriers, the letter argues, can leave small, volunteer-led software teams without the same technical capabilities available to well-resourced attackers.

Bitcoin Policy Institute wrote that Bitcoin secures more than $1 trillion in value and that vulnerabilities in widely deployed open-source components can expose personal savings and financial services. The proposed programs would give screened defenders a route to use advanced models for security reviews, code analysis and response work before threats become public incidents.

Signatories seek standing access for security teams

The letter was signed by a mix of infrastructure providers, Bitcoin-focused organizations and wallet manufacturers, including the African Bitcoin Institute, Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, MARA, Ledger and Trezor.

That range of support reflects how many parts of the crypto sector depend on relatively small groups of open-source maintainers. A flaw in a wallet library, cryptographic implementation or software dependency can reach far beyond the original project if it is integrated into products used by custodians, payment providers or individual holders.

The signatories did not set a deadline for AI labs to respond or name particular companies that should receive access. They instead called for a durable process that would let approved defenders work with frontier systems under safeguards designed for sensitive cybersecurity use.

Such programs already exist in various forms across the AI sector, generally allowing selected researchers and organizations to test advanced systems with stronger monitoring and contractual controls than are available through ordinary consumer products. The coalition’s request is that open-source financial infrastructure teams be treated as a distinct security constituency within those programs.

AI changes the economics of bug hunting

The letter describes frontier models as tools that can scan extensive codebases, identify suspicious patterns and accelerate complex technical tasks. Those capabilities can help developers find and fix weaknesses, but they can also reduce the time and expertise required to search for exploitable flaws.

For an open-source project, that creates a resource problem. Attackers need only uncover one viable weakness, while maintainers must assess reports, reproduce potential issues, write patches and coordinate a safe release. AI-generated findings could increase the volume of work on both sides, including by producing false positives that consume already limited reviewer time.

Bitcoin Policy Institute said it had received multiple independent reports from open-source maintainers describing advanced actors using AI capabilities to sustain attacks, including actors the institute characterized as potential foreign adversaries. The letter did not provide specific examples or identify the affected projects.

The absence of detailed incident descriptions leaves the immediate scale of AI-driven attacks difficult to measure. Yet the appeal is grounded in an increasingly practical concern: security work is likely to become more automated, while many essential open-source projects remain dependent on small teams and public contributions.

The group is therefore asking AI labs to view access as part of defensive capacity. Early use of highly capable systems could allow maintainers to audit major changes, trace complex interactions between software components and investigate reports before a vulnerability is exploited at scale.

Recent losses underscore the pressure on defenders

Cryptocurrency theft has remained a costly reminder of how quickly software and operational failures can turn into financial losses. DefiLlama recorded more than $634 million stolen from cryptocurrency platforms in April 2026. Its data also shows roughly $1.4 billion in losses during February 2025, a month that included the attack on Bybit.

Those figures cover a broad set of incidents and do not demonstrate that AI caused the breaches. They do show the financial stakes for teams maintaining systems that hold or move digital assets, particularly where a single vulnerability can expose funds across multiple users or applications.

Security concerns have also accompanied the release of increasingly capable AI models, including Claude Opus 4.8 and ChatGPT 5.5, according to the source material. Mitchell Amador, chief executive of bug bounty platform Immunefi, has described the trend as a “vulnerability apocalypse” for the crypto industry.

That phrasing is intentionally stark, but the underlying concern is straightforward: automated tools can make vulnerability discovery faster, while the process of responsibly fixing a security issue remains constrained by testing, coordination and the need to avoid exposing users during a patch rollout.

Access would not replace conventional security practices

Trusted AI access would add a tool to the defensive stack rather than resolve the underlying maintenance problem. Models can identify suspicious code or propose testing paths, but experienced developers must validate results, distinguish genuine findings from noise and decide how to deploy a fix safely.

The request also places frontier AI labs closer to the operational security of financial infrastructure without asking them to take responsibility for the code itself. Labs would need to determine eligibility standards, prevent access from being abused and maintain rules for handling sensitive vulnerability information.

For Bitcoin Core and similar projects, a structured program could reduce the gap between publicly available AI tools and systems reserved for high-trust security users. Whether the major labs consider open-source financial maintainers eligible for that category will determine whether the letter leads to a concrete new channel for defensive research or remains a warning about an imbalance already taking shape.


Concerned about AI-powered exploits in crypto? Strengthen your defenses by learning essential crypto safety standards every trader must know.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up