Robotic hand holding a digital globe with connected network icons representing blockchain, security, and data technology
TECHNOLOGY

Bitcoin Firms Urge AI Labs to Give Security Researchers Equal Access to Frontier Models

Image Credit: Shutterstock

Key Takeaways

  • Over three dozen Bitcoin firms, including Coinbase, Block, and BitGo, signed a letter asking AI labs to give security researchers trusted-partner-level access to frontier models.
  • The letter argues public model safety filters block legitimate vulnerability research while attackers exploit offensive AI capabilities months before defenders gain access.
  • The request follows a critical BTCPay Server flaw that drained Lightning nodes, discovered by a volunteer group already using AI to scan Bitcoin codebases.

More than three dozen Bitcoin and crypto companies have asked the largest artificial intelligence labs to give open-source security researchers early access to their most capable models. The companies argue that the people defending roughly a trillion dollars of Bitcoin infrastructure are currently working with weaker AI tools than the attackers targeting it.

More Than Three Dozen Firms Sign On

The letter, organized by the Bitcoin Policy Institute and published earlier this week, carries signatures from Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa and Exodus, among others. 

Nonprofit developer funds including Brink, Chaincode and Btrust also signed, reflecting support from both commercial firms and the organizations that fund independent Bitcoin software development.

The Core Complaint: Defenders Locked Out of Trusted-Partner Programs

The letter’s central argument focuses on Bitcoin Core developers, the small group of engineers who maintain the software underlying the Bitcoin network. 

According to the letter, these developers cannot access the programs major AI labs run for trusted security partners, arrangements that typically give vetted researchers deeper access to a model’s capabilities than the public receives.

When Bitcoin Core developers turn to publicly available models instead, the letter states, the safety filters designed to prevent people from writing malware also block legitimate efforts to find vulnerabilities before criminals exploit them. 

That leaves defenders relying on open-weight models, which can be downloaded freely but are generally less capable than the frontier systems labs keep behind trusted-partner programs.

The letter argues attackers face no equivalent restriction. It states that labs and a few partners see new offensive AI capabilities months before the wider security community does. Those same capabilities eventually spread through public model releases, stolen access to corporate systems and purpose-built hacking tools regardless of the guardrails in place.

Five Specific Requests to AI Labs

The signatories outlined five specific requests. They are asking for early access to the strongest cyber-capable models, including before public release, and sufficient computing budget to run meaningful security reviews.

They are also requesting secure environments for examining private code, eligibility criteria that include small and independent maintainers rather than only large firms, and a direct channel to lab security teams for reporting vulnerabilities they find.

A Recent Exploit Illustrates the Stakes

The letter’s timing follows two related developments among its own signatories. BTCPay Server, a payment processor that signed the letter, disclosed a critical flaw last week that attackers had already exploited to drain Lightning network nodes belonging to merchants. Foundation, a hardware wallet maker that also signed the letter, lost its own node in that same attack.

BTCPay wrote following the disclosure that artificial intelligence is changing the balance between attackers and defenders, noting that AI models make it faster and cheaper to search large codebases for weaknesses. The letter’s signatories argue that dynamic currently favors attackers with fewer access restrictions.

Volunteer Researchers Already Filling the Gap

Despite the access constraints described in the letter, defenders identified the BTCPay flaw themselves. A volunteer group calling itself the Bitcoin Red Team began pointing AI models at Bitcoin-related codebases earlier this month and has filed thousands of vulnerability findings across hundreds of projects, including the specific report that led to BTCPay’s patch.

That effort shows current tools, even with restrictions, can still surface serious flaws. The letter’s signatories argue broader access would let that work scale faster and catch more issues before attackers do.

More For You

Explore More News