Published Invest3 min read
Crypto's $1T defenders ask AI labs for keys to the models attackers already have
More than 40 Bitcoin and digital-asset firms, coordinated by the Bitcoin Policy Institute, want vetted researcher access to frontier models. The ask is governance, not capability.
Context for builders, not their beat.See today for builders

What happened
- More than 40 Bitcoin and digital-asset organizations are asking leading AI labs to give vetted open-source security researchers controlled access to frontier models.
- The request is coordinated by the Bitcoin Policy Institute (BPI) and frames access to technologies including those from OpenAI and Anthropic as a defensive imperative.
- The software the letter refers to protects over $1 trillion worth of assets.
- The Bitcoin Policy Institute says attackers can already use advanced or locally deployed AI tools, while legitimate defenders may be blocked by safety filters or access limits.
- The BPI letter acknowledges the technology is dual-use: models that allow a programmer to search for problems in a large system also allow a malicious user to do the same.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
More than 40 Bitcoin and digital-asset organisations have asked leading AI labs to give vetted open-source security researchers controlled access to frontier models [1]. The letter, coordinated by the Bitcoin Policy Institute, presents access to systems from labs including OpenAI and Anthropic as a defensive requirement for code protecting more than $1 trillion in assets [2][3].
The argument is narrower than a complaint about censorship. BPI's position is that attackers can already reach advanced or locally deployed AI tools, while legitimate defenders are stopped by safety filters or access limits [4]. When a frontier system declines a security prompt, or puts a capability behind a programme that open-source financial infrastructure cannot join, maintainers fall back to weaker open-weight models, and attackers operate under no such constraint, according to the letter [6]. The signatories concede the tooling is dual-use: a model that helps a programmer find flaws in a large system helps a malicious user do the same [5]. What they are asking for is not fewer guardrails for everyone [8], but "standing trusted-access programs for qualified defenders of open-source financial infrastructure," entered through an evaluation process [7].
The loss data gives the request weight without settling it. SlowMist recorded 182 incidents and about $956 million in H1 2026 losses; TRM Labs counted 207 hacks and $972 million [9][10]. The two tallies differ by 25 incidents and roughly $16 million [11], which says something about how loose the measurement is, and both land near a tenth of a percent of the $1 trillion the signatories say they secure [12]. As an annualised loss rate on assets under custody, that is survivable. The stronger claim is about who is attacking: BPI says it has received independent reports from open-source maintainers describing sophisticated attackers using advanced AI, some possibly foreign adversaries [15].
Signatory quality carries this more than the headcount. Block, Coinbase, Strategy, MARA, Galaxy, BitGo, Brink, OpenSats, Chaincode Labs, Spiral, Trezor, Unchained, Btrust and Fedi are among the names reported by crypto.news [13], with Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry and BTCPay Server reported by NewsBTC [14]. That puts exchanges, custodians, miners, corporate treasuries and the protocol maintainers themselves on one document, which is unusual and makes the letter harder for a lab's policy team to file away.
There is evidence models find real defects. An Ethereum Foundation study in July used coordinated AI agents to surface genuine vulnerabilities, including a libp2p flaw later disclosed as CVE-2026-34219 [21].
The awkward part is that restricted access may be a depreciating asset. Bitcoin red team contributor Calle wrote on X on 13 August that the work represented "a massive collision between decades of human open source slop against 2 weeks of kimi k3" [16]; Kimi comes from the Chinese lab Moonshot [17]. CSIS analyst Yasir Atalan said in July that Chinese models are "now months, not years" behind American ones, citing a government study that put DeepSeek V4-Pro, the best Chinese open-weight model, about eight months behind US leaders [18]. Stanford AI Index data published in 2026 counted 59 important US models in 2025 against China's 35, roughly 1.7 times as many, though China leads on research and patent output [19][20]. A defensive edge rented from US labs erodes as open-weight rivals catch up.
Watch whether a single lab actually stands up a vetting programme, who administers the vetting, and what liability the lab accepts for a credentialed researcher. Watch also whether the perimeter stays at Bitcoin, because every other open-source maintainer of financial plumbing has the same argument available.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
More than 40 Bitcoin and digital-asset organizations are asking leading AI labs to give vetted open-source security researchers controlled access to frontier models.
- [2]
The request is coordinated by the Bitcoin Policy Institute (BPI) and frames access to technologies including those from OpenAI and Anthropic as a defensive imperative.
- [3]
The software the letter refers to protects over $1 trillion worth of assets.
- [4]
The Bitcoin Policy Institute says attackers can already use advanced or locally deployed AI tools, while legitimate defenders may be blocked by safety filters or access limits.
- [5]
The BPI letter acknowledges the technology is dual-use: models that allow a programmer to search for problems in a large system also allow a malicious user to do the same.
- [6]
According to the letter, when frontier systems ignore security prompts or lock key functionality behind programmes that open-source financial architecture cannot use, maintainers are forced to resort to weaker open-weight models, while attackers are not under such constraints.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cryptopolitan.comMicah AbiodunAug 13Bitcoin Red Team, BPI and 40+ firms join forces to close the AI security Gap
Additional citations
- Cryptopolitan
- Bitcoin Policy Institute letter, via Cryptopolitan
- Bitcoin Policy Institute
- Bitcoin Policy Institute letter
- SlowMist, via Cryptopolitan
- TRM Labs, via Cryptopolitan
- crypto.news, via Cryptopolitan
- NewsBTC, via Cryptopolitan
- Calle on X, via Cryptopolitan
- Yasir Atalan, CSIS, via Cryptopolitan
- Stanford AI Index, via Cryptopolitan
- Ethereum Foundation study, via Cryptopolitan


