On August 10, the Bitcoin Policy Institute published an open letter, signed by more than 70 organizations in the crypto-asset ecosystem, calling on frontier AI labs to create trusted access programs for open-source security defenders. The document argues that current restrictions prevent legitimate researchers from using the strongest models and force them to rely on less capable alternatives, while sophisticated attackers do not face the same limits.

Pressure on the sector increased after a firmware flaw in Coldcard hardware wallets was exploited starting July 30, resulting in the theft of more than US$ 100 million in bitcoin. In response, a volunteer group called Bitcoin Red Team, led by open-source developer Calle and Rob Hamilton, CEO of AnchorWatch, conducted AI-assisted audits of bitcoin repositories, mainly using the Chinese open-source model Kimi K3.

By August 8, after more than 100 hours of work with dozens of collaborators, the group reported having scanned 501 projects and produced 7,958 findings, of which 1,280 were classified as high or critical severity. Most of the computational cost continued to go to Chinese open-weight models.

American model restrictions

Rob Hamilton said that after joining OpenAI's cybersecurity program and having completed KYC verification months earlier, he was blocked when analyzing a codebase he had already responsibly disclosed. “This destroys me as a patriotic American, but I will go back to using Chinese open-source models to conduct my research and protect Bitcoin’s infrastructure,” he wrote. Days later, he obtained access to OpenAI's “Daybreak Blue” model and was blocked again within 19 minutes during a security test on Bitcoin's infrastructure.

Francis Pouliot, founder of Bull Bitcoin, said he had never seen OpenAI so restricted. “The US AI industry is completely destroyed if it doesn't change this path,” he posted. In a follow-up post, Pouliot detailed how a Chinese open-source model identified an exploit that was stealing money from a project he was auditing, demonstrated the attack, and helped fix it. When he asked American models to review the same fix, they refused.

PortlandHODL, a Bitcoin Core contributor and AnchorWatch developer, highlighted the performance difference. “American frontier model: ‘You are absolutely right!’ Chinese open-source model: ‘78 critical vulnerabilities found.’,” he posted. He asked that OpenAI and Anthropic create adequate access programs for American citizens doing defensive security work.

Lessons from the audit campaign

Calle shared lessons from the intensive testing period. According to him, the effort completed a basic scan of virtually the entire Bitcoin open-source ecosystem, and the easiest vulnerabilities were largely exhausted. He warned that the exclusively human era of open-source security review has ended: verification is now practically free, and information overload must be managed with AI.

Calle also repeatedly emphasized that developers must stop writing security-critical code in C. “We are finding memory safety vulnerabilities in C projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow was not enough. You would need a highly skilled hacker to turn the vulnerability into a functional exploit. Today, that is a single prompt,” he explained.

Bitcoin was the first major open-source ecosystem to face this collision between accumulated human code and the capability of frontier AI. The rest of the software world is expected to follow the same path.

More from Radar