Bitcoin developers could fall behind attackers without top AI models, BPI says

Bitcoin developers could fall behind attackers without top AI models, BPI says

A group of crypto companies and industry organizations has called on frontier AI labs to give Bitcoin and other open-source financial infrastructure developers trusted access to their most capable models as AI-assisted cyber threats become more advanced.

Summary
  • Crypto companies have urged frontier AI labs to give Bitcoin and open source financial infrastructure developers trusted access to their most capable models.
  • The Bitcoin Policy Institute said current restrictions can leave qualified defenders relying on less capable AI tools while sophisticated attackers gain access to advanced systems.
  • Anchorage Digital, BitGo, Bitwise, Blockstream, Kraken, Ledger, MARA and Trezor were among the companies and organizations that signed the open letter.
  • BPI said advanced AI can help defenders scan large codebases and find vulnerabilities faster, but the same capabilities can also be used by attackers.

The Bitcoin Policy Institute said in an open letter published Monday that developers responsible for securing open-source financial systems can be excluded from specialist cyber programs or restricted by safeguards built into publicly available frontier AI models.

Bitcoin developers seek access to stronger AI security tools

Under the proposal, AI companies would “establish or expand standing trusted-access programs for qualified defenders of open-source financial infrastructure,” allowing vetted security researchers and maintainers to use capabilities that may otherwise be restricted.

BPI argued that access has become more important as advanced AI systems gain the ability to examine large codebases, identify potential vulnerabilities and speed up difficult technical work. These capabilities can help legitimate researchers find flaws, but the institute said they can also be used by attackers looking for weaknesses.

For Bitcoin developers, the letter said the access gap can leave maintainers dependent on less capable open-weight models when frontier systems either refuse security-related requests or remain available only through programs that do not include open-source financial infrastructure.

The institute pointed to the amount of capital dependent on such software, noting that Bitcoin alone secures more than $1 trillion in value. A serious vulnerability in financial infrastructure can therefore put users’ savings at risk, the letter said.

Several major crypto companies joined the request, including Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, MARA, Kraken, Ledger and Trezor. The African Bitcoin Institute was also among the organizations that signed the letter.

Bitcoin Core’s recent security work has provided examples of the type of vulnerabilities maintainers must identify before they can affect users. In June, crypto.news previously reported that Bitcoin Core 31.1rc1 fixed a privacy problem involving PrivateBroadcast that could expose a user’s IP address under certain network conditions. The release candidate also contained changes covering wallet accuracy, networking, blockchain validation, and MuSig2 security.

A month earlier, Bitcoin Core developers disclosed a high-severity bug tracked as CVE-2024-52911 that could allow miners to remotely crash some nodes. The vulnerability affected versions after 0.14.0 and before 29.0, although triggering it required miners to produce costly proof-of-work blocks. Security researcher Cory Fields privately reported the flaw in 2024 before Bitcoin Core 29.0 shipped with the fix in April 2025.

Frontier AI could strengthen open-source defenders

BPI described frontier AI as a technology that is changing the economics of both cybersecurity research and cyber operations because increasingly capable models can perform tasks that previously required substantial amounts of specialist human work.

Advanced models could eventually become one of the “most powerful defensive technologies ever developed,” the institute said, particularly when researchers use them to inspect software and identify weaknesses before attackers exploit them.

“Without dedicated access programs, defenders may lack the tools needed to keep pace with evolving threats to the infrastructure they maintain,” the letter said.

BPI also said it had received multiple independent reports from open-source maintainers about sophisticated actors using advanced AI capabilities to sustain attacks. Some of the activity potentially involved foreign adversaries, according to the institute.

Rather than asking AI developers to remove security controls from their models for all users, the signatories are seeking standing programs through which qualified defenders could receive additional access after being vetted.

The proposal would put open-source financial developers closer to researchers and organizations already permitted to use advanced cyber capabilities under controlled programs, while retaining restrictions intended to prevent unrestricted access by malicious users.

The potential defensive value of AI has already been tested elsewhere in crypto. In July, an Ethereum Foundation study found that coordinated AI agents could uncover genuine vulnerabilities in software used by Ethereum, including a libp2p flaw later disclosed as CVE-2026-34219. The Foundation’s Protocol Security team said the harder part was determining which AI-generated reports represented real vulnerabilities rather than convincing false positives.

Human validation and reproducible proof therefore remained necessary even when AI systems successfully identified security problems, according to the Foundation.

AI-assisted attacks raise pressure on crypto security

The request comes after crypto platforms suffered another heavy period of security losses in 2026, with attackers increasingly able to combine software vulnerabilities, compromised credentials, social engineering and other attack methods.

DefiLlama data cited in June showed more than $634 million was stolen from cryptocurrency platforms during April, the industry’s highest monthly loss since the Bybit hack, which contributed to roughly $1.4 billion in losses in February 2025.

Earlier figures covered in April showed more than $606 million had already been stolen across 12 incidents during the first 18 days of the month. The amount was roughly 3.7 times the $165.5 million lost throughout the first quarter of 2026.

Two attacks accounted for most of April’s losses at that stage. Drift Protocol lost about $285 million, while an exploit involving KelpDAO resulted in losses of roughly $292 million, with the two incidents accounting for about 95% of the reported total during the first 18 days.

The attack pattern has also moved outside isolated smart-contract bugs. DefiLlama had recorded more than $17 billion in losses across 518 crypto hacking incidents over the previous decade by April, with private-key leaks, phishing and credential theft accounting for an increasing part of the damage alongside protocol exploits.

At the same time, security companies have warned that AI can lower the amount of time and technical work required to search for exploitable weaknesses. CertiK said in April that AI-assisted phishing, deepfakes and automated exploit tools were making attacks faster and harder to detect, while cross-chain infrastructure and social engineering remained important attack routes.

Advanced AI models have changed vulnerability discovery

Concerns over access have intensified as frontier models demonstrate stronger vulnerability-discovery capabilities, giving security researchers tools that can inspect software at a scale that was previously difficult to achieve.

Mitchell Amador, CEO of bug bounty platform Immunefi, described the proliferation of systems including Claude Opus 4.8 and ChatGPT 5.5 as contributing to a “vulnerability apocalypse” for crypto security, arguing that advanced models had changed the balance between attackers and defenders.

Amador said the next three to four years could be critical for crypto cybersecurity while defensive teams work to use the same AI capabilities to produce more secure codebases. Increased use of crowdsourced security systems could shorten that period to less than two years, he added.

AI-based security tools were already part of the industry’s defensive infrastructure before the latest concerns. In an October 2025 interview with Immunefi, Amador said automated vulnerability detection should operate alongside audits, bug bounties, monitoring systems and transaction firewalls rather than replace them. He said at the time that fewer than 10% of projects used AI vulnerability tools.

Ethereum co-founder Vitalik Buterin made a similar case for defensive uses in May, arguing that AI-assisted formal verification could eventually allow developers to combine highly optimized software with machine-checked proofs of correctness. He cited potential applications across Ethereum’s consensus systems, zero-knowledge technology, and quantum-resistant cryptography while cautioning that formal verification could not eliminate every source of software risk.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *