Bitcoin firm leaders and open-source builders are publicly stating that Chinese language AI fashions are at present outperforming restricted American frontier programs in defensive cybersecurity work, forcing researchers to depend on them to safe vital Bitcoin infrastructure.
Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance coverage firm, reported cripling American AI restrictions. After integrating OpenAI’s trusted cyber program (having already accomplished KYC months earlier), he was blocked from additional evaluation on a codebase he had already responsibly disclosed. “It completely guts me as a patriotic American to have to do that, however I might be going again to utilizing Chinese language open supply fashions to conduct my analysis to guard Bitcoin infrastructure,” Hamilton wrote. “Black hats is not going to hit these points. The white hats will.” Days later, he gained entry to OpenAI’s “Dawn Blue” cyber mannequin and was blocked again within 19 minutes whereas red-teaming Bitcoin infrastructure.
Francis Pouliot, founding father of Bull Bitcoin, a Bitcoin-only change centered on self-custody infrastructure, described the scenario bluntly. “I’ve by no means seen OpenAI this cucked. It’s cucked past perception now. Not even for safety, for something associated to Bitcoin,” he posted. “USA AI business is totally cooked in the event that they don’t change this path,” he concluded, including “Open-source Chinese language LLMs. [orange heart emoji],” which means that open Chinese language fashions like Kimi K3 are literally useful to Bitcoin. In a follow-up, Pouliot detailed how a Chinese language open-source mannequin recognized a money-stealing exploit in a mission he was auditing, demonstrated it on regtest, and helped patch it. When he requested the American fashions he pays for to evaluate the identical patch, they refused.
PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, publicly highlighted the efficiency hole. “US-based Frontier AI Mannequin – ‘You’re completely proper!’ Chinese language Open Mannequin – ‘78 vital vulnerabilities discovered.’ The implications of this are unfathomable,” he posted. In a follow-up, he added that he felt he was “principally asking Xi to not get my software program hacked at this level,” calling for OpenAI and Anthropic to create correct entry packages for U.S. residents doing defensive safety work.
Alex Thorn, Head of Firmwide Analysis at Galaxy, signed a current Bitcoin Coverage Institute open letter demanding trusted entry to frontier fashions for open-source defenders. “Individuals shouldn’t should depend on Chinese language AI to defend themselves, their initiatives, corporations, or shoppers from cyber-attacks,” he wrote. “RED TEAM NEEDS THE MODELS.”
On August 10, the Bitcoin Coverage Institute — a Bitcoin and, of late, AI-focused coverage assume tank — revealed an open letter signed by greater than 70 organizations throughout the digital-asset ecosystem, together with main custodians, exchanges, mining companies, and open-source growth teams. The letter calls on frontier AI labs to ascertain clear trusted-access packages for certified open-source and digital-asset defenders. It argues that present restrictions and security guardrails depart legit safety researchers with out entry to the strongest fashions, forcing them to depend on much less succesful open-weight alternate options whereas subtle attackers face no such limits. The signatories request early entry to cyber-capable fashions, enough compute, safe environments for reviewing code, and direct channels with lab safety groups, stating that frontier AI might grow to be some of the highly effective defensive applied sciences obtainable if defenders are given honest entry.
These statements mirror a broad sample amongst Bitcoin safety researchers: American fashions from OpenAI and Anthropic ceaselessly refuse or limit legit defensive work, even to customers who’re purported to have been granted express entry, whereas Chinese language fashions resembling Kimi K3 function with out the identical guardrails and are delivering confirmed outcomes. Issues about internet hosting infrastructure of Chinese language fashions being an assault vector can be mitigated, since they’re open supply and may be run on American-hosted knowledge facilities, a development that’s prone to threaten the U.S. AI market if it continues.
Coldcard Exploit Triggers Ecosystem-Broad Response
The cybersecurity strain turned acute within the Bitcoin business after a firmware flaw in Coldcard hardware wallets was exploited starting July 30, ensuing within the theft of properly over $100 million in bitcoin from seeds generated with inadequate entropy. Bitcoin Journal revealed an pressing advisory urging affected customers emigrate funds: COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED.
In response, a volunteer effort generally known as the Bitcoin Pink Crew shaped, led by open-source developer Calle (creator of Cashu and the Android model of Bitchat) and Rob Hamilton. The group has performed large-scale AI-assisted audits of Bitcoin open-source repositories, utilizing fashions together with Kimi K3 as the first workhorse alongside restricted entry to Western programs. Early outcomes, lined by Bitcoin Journal, confirmed thousands of findings across hundreds of projects, together with dozens of vital points, with spending lined largely by OpenSats.
By August 8, after greater than 100 hours of labor involving dozens of contributors, the workforce reported scanning 501 initiatives and producing 7,958 findings, of which 1,280 had been rated excessive or vital severity. The vast majority of compute spend continued to go to Chinese language open-weight fashions.
Classes from the Pink Crew Marketing campaign
Most just lately, Calle shared lessons from the intensive red-team interval. The hassle has primarily accomplished a primary scan of just about all the Bitcoin open-source panorama; low-hanging fruit is essentially exhausted, the developer wrote on this X account. Maintainers throughout initiatives have validated most of the vital and high-severity studies, whereas response instances from initiatives fluctuate extensively and function a sign of total well being.
Key takeaways embrace the necessity for each mission to keep up its personal everlasting AI audit pipeline going ahead. Tasks that started such evaluations months earlier are in a markedly stronger place. Unmaintained repositories must be handled as possible damaged and unreliable.
Calle additionally warned that the human-only period of open-source safety evaluate is over; verification is now successfully free, and data overload should be dealt with with AI fairly than complaints about PR slop. A number of concurrent and numerous human approaches stay the strongest methodology for locating vulnerabilities, and exterior red-teaming will possible be required indefinitely.
Calle additionally repeatedly emphasised that builders ought to cease writing security-critical code in C. In a follow-up post he defined: “we’re discovering memory-safety vulnerabilities in c initiatives which are prevented by default in lots of different languages. Prior to now, discovering a easy buffer overflow wasn’t sufficient. You’d want a extremely expert hacker to show the vulnerability right into a working end-to-end exploit. In the present day, that’s a single immediate.”
Bitcoin was the primary main open-source ecosystem to confront this collision between accrued human code and frontier AI functionality. The remainder of the software program world is predicted to comply with.
