Over 40 Crypto Firms Sound the Alarm on AI’s Security Divide
More than 40 Bitcoin and digital-asset organizations are asking leading artificial intelligence (AI) labs to give vetted open-source security researchers controlled early access to powerful AI systems, arguing that attackers are gaining an unfair advantage.

Key Takeaways
- More than 40 groups, including Coinbase, signed the Aug. 10 artificial intelligence (AI)-access letter.
- Bitcoin’s $1 trillion-plus ecosystem faces faster AI-assisted vulnerability searches.
- AI labs may respond to five requested access measures in the coming months.
The Bitcoin Policy Institute published the open letter, titled “Defenders Need the Frontier,” on Aug. 10. Its signers include Coinbase, Bitgo, Block, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Strategy, MARA, Galaxy, Trezor, and developer-support groups such as Brink, Chaincode Labs, Btrust, OpenSats, and BTCPay Server.
A Race Between Attackers and Defenders
The request centers on a changing reality in cybersecurity. Advanced AI systems can scan huge collections of computer code, identify possible weaknesses, and help researchers test whether a flaw can be exploited.
That can make security reviews faster and more thorough. It can also make attacks cheaper and easier to scale. The news follows Coldcard’s recent breach, where AI was suspected of spotting the hardware wallet’s firmware flaw before it went boom.

The coalition says large AI labs and a small group of selected partners often get early visibility into those capabilities, while the people maintaining widely used open-source financial software do not. By the time stronger tools become broadly available, the letter argues, attackers may already have found ways to access, copy, or build comparable capabilities.
“Frontier AI is changing the economics of both security research and cyber operations,” the letter says. It warns that defenders frequently face safety restrictions when they try to use public AI products for legitimate research, leaving them “to rely on less capable open-weight alternatives for critical security reviews.”

Open-weight models are AI systems whose underlying software can be downloaded and adapted by outside developers. They can be useful, but the coalition says they may not match the strongest models available from major labs. The difference matters when a small team must inspect complex software that handles real money.
What is at risk
Bitcoin alone secures more than $1 trillion in value, according to the letter. The broader digital-asset system also depends on open-source software for wallets, cryptographic libraries, payment processors, exchanges, custody services, and Lightning Network tools.
A flaw in any of those pieces can have serious consequences. Digital assets often function like bearer instruments: Control of the cryptographic credentials can mean control of the funds. Once money is moved, recovery can be difficult or impossible.
That makes rapid detection especially important for consumers holding savings, merchants accepting bitcoin payments, and businesses that safeguard client assets. The coalition argues that security weaknesses can expose retirement accounts, business funds, emergency savings, and institutional capital, not merely software systems.
The letter says the strain is already visible among small maintenance teams. It says the Bitcoin Policy Institute has received reports that sophisticated actors, including possible foreign adversaries, are using advanced AI capabilities to sustain pressure on open-source developers. Even unsuccessful attacks can consume time and money that maintainers would otherwise spend improving their software.
A Recent Audit Showed AI’s Defensive Power
The push follows an early-August volunteer project called the Bitcoin Red Team, which used AI-assisted tools to audit Bitcoin-related code. Participants included Cashu developer Calle and Anchorwatch CEO Rob Hamilton.

In one early snapshot posted to X, the group reviewed 390 projects in about 27.5 hours and filed roughly 4,962 findings. Those included dozens classified as critical, and hundreds considered high severity. The team used several AI systems, including Moonshot’s Kimi K3, OpenAI systems, and Anthropic’s Claude variants, while Opensats helped fund compute costs reported in the tens of thousands of dollars.
Such findings are not automatically confirmed vulnerabilities. AI-generated reports still require experienced people to verify them, assess their severity, and coordinate repairs. But the scale of the effort showed how quickly AI can help security researchers sort through complex code that might otherwise take much longer to examine.
The coalition says access limits forced the group to depend heavily on available models during its initial work. Its broader argument is that qualified defenders should be able to use the most capable systems before those systems become common tools for criminals or hostile governments.
A Real Breach Raised the Stakes
The debate became more urgent after BTCPay Server disclosed a critical flaw affecting versions before 2.4.2. BTCPay is open-source software that helps merchants accept Bitcoin payments.
The vulnerability could allow an unauthenticated remote attacker to obtain sensitive administrator credentials for LND, a commonly used Lightning Network implementation. Those credentials could give an attacker control of connected wallets and allow funds to be drained. The flaw was actively exploited, and some operators reported losses.
The incident gave the letter’s argument a concrete example. Bitcoin Red Team members helped analyze the issue, while Sparrow Wallet developer Craig Raw played a key role in identifying it after being affected, according to the source report. BTCPay said AI is changing the balance between attackers and defenders by lowering the cost of reviewing large codebases.
The Coalition Is Not Asking for Open Release
The signers are not calling for unrestricted public access to the most cyber-capable AI models. Instead, they want standing trusted-access programs for people and groups that can demonstrate legitimate security responsibilities.
Their proposed programs would offer early, controlled access to advanced models, including prerelease systems when appropriate. They also seek enough computing capacity for long-running AI tasks, secure spaces to inspect private or embargoed code, and direct communication channels with lab security teams.
The letter specifically asks labs not to limit eligibility to major companies and governments. Small nonprofits, independent maintainers and volunteer developers often protect software used by millions of people, it says, yet may lack the resources or institutional ties needed to enter existing programs.
“Defenders need the frontier,” the letter concludes. “Please give them a fair head start.”
What happens next will depend on whether leading AI labs expand specialized cybersecurity access programs and whether they include open-source financial infrastructure in their eligibility rules. The letter remains open for additional signatures, and bitcoin users, merchants, and investors should watch for lab responses, new audit results, and further disclosures from software projects that rely on AI-assisted security reviews.
