Bitcoin Firms Push AI Labs for Defensive Tools Against Crypto Hackers

More than 30 Bitcoin and crypto companies are urging major AI developers to provide open-source security researchers with early access to their most advanced models. The companies argue that the developers responsible for protecting critical crypto infrastructure often lack the same sophisticated AI capabilities available to potential attackers.

The appeal was organized by the Bitcoin Policy Institute and published earlier this week. Signatories include Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa and Exodus, along with nonprofit developer organizations such as Brink, Chaincode and Btrust.

The letter focuses heavily on the challenges faced by Bitcoin Core developers, the relatively small community responsible for maintaining the software that powers the Bitcoin network. According to the group, these developers generally cannot access the advanced AI systems that labs provide to selected cybersecurity partners.

Publicly available AI models present another obstacle. Safety restrictions designed to prevent the generation of malicious code can also interfere with legitimate vulnerability research, potentially preventing developers from using AI to uncover weaknesses before criminals find them.

Researchers are therefore often left relying on open-weight models, which can be downloaded and operated more freely but tend to be less capable than the latest closed models.

The signatories argue that cyber attackers operate without similar limitations. AI labs and a small group of trusted partners may receive access to new offensive capabilities months before the broader public, while comparable tools can eventually circulate through public AI systems, compromised corporate accounts and specialized hacking software.

What Bitcoin Firms Are Asking AI Labs to Provide

The companies have outlined five specific requests. They want early access to the most powerful cybersecurity-capable AI models, including systems that have not yet been publicly released; sufficient computing resources to conduct large-scale security reviews; secure environments for analyzing sensitive or private code; access programs that include independent researchers and smaller development teams; and direct communication channels with AI labs’ security teams for reporting vulnerabilities.

The request comes at a time when recent attacks have highlighted the growing role of AI in cybersecurity.

BTCPay Server, which signed the letter, recently disclosed a critical vulnerability that attackers had already exploited to drain Lightning nodes operated by merchants. Foundation, a hardware wallet manufacturer and another signatory, also lost one of its nodes in the attack.

BTCPay later noted that AI is changing the cybersecurity landscape by allowing both attackers and defenders to scan large codebases for vulnerabilities more quickly and at a lower cost.

In this case, the vulnerability was ultimately uncovered by defenders. A volunteer group called the Bitcoin Red Team began using AI models to examine Bitcoin-related codebases earlier this month and has submitted thousands of security findings across hundreds of projects.

One of those discoveries led directly to the vulnerability report that prompted BTCPay Server to issue its security patch.