More than three dozen Bitcoin and cryptocurrency companies have appealed to leading AI labs, calling for them to provide open-source developers with early access to the most powerful cybersecurity models. The corresponding open letter was organized by the Bitcoin Policy Institute. Signatories include Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, Exodus, as well as the Brink, Chaincode, and Btrust funds.
The authors of the appeal stated that Bitcoin Core and other developers of critical financial infrastructure are working with less powerful AI tools than potential attackers. According to them, the safety guardrails of public models, designed to block the creation of malicious code, sometimes hinder legitimate vulnerability research.
At the same time, new cyber capabilities are spreading through open-weight models, stolen access to corporate systems, and specialized tools.
"Cutting-edge AI is changing the economics of both security research and cyber operations," the letter states.
In the signatories' view, early access to advanced models would allow for faster discovery and patching of vulnerabilities in the software that protects trillions of dollars in digital assets.
They emphasized that the Bitcoin network alone secures assets worth over $1 trillion, and a vulnerability in related infrastructure could jeopardize user funds.
What Exactly Are Crypto Companies Asking For
The signatories urged AI labs to create permanent trusted access programs that would include:
- early access to the most powerful models with cyber capabilities;
- sufficient computational resources for extended testing;
- secured environments for analyzing private code;
- participation of small teams, non-profit organizations, and independent developers;
- a direct communication channel with the AI labs' security teams.
The relevance of such access has already been demonstrated by recent attacks. BTCPay Server, a signatory of the letter, disclosed a critical vulnerability that attackers used to target merchants' Lightning nodes. The vulnerability was discovered by the Bitcoin Red Team group, which this month began using AI models to audit Bitcoin codebases and has already submitted thousands of reports on potential issues across hundreds of projects.
The scale of the attack on Coldcard also demonstrated how severe the consequences of errors in cryptographic infrastructure can be.
According to SlowMist, attackers stole at least 1,719 $BTC worth approximately $111 million, with the funds linked to over 5,200 addresses.
Researchers reproduced the attack chain and determined that due to a configuration error, the STM32 hardware random number generator was disabled, causing the system to use the predictable Yasmarang software generator. This significantly reduced the entropy level and allowed attackers to brute-force possible values, recover seed phrases, and drain vulnerable wallets.
Critical Vulnerabilities Already Leading to Multi-Million Dollar Losses
The issue of access to advanced AI tools is particularly relevant against the backdrop of a series of attacks on cryptocurrency infrastructure in 2026.
Specifically, in July, the DeFi protocol Ostium lost about $24 million due to a vulnerability in its price oracle update mechanism, and AFX on the Arbitrum network lost over $24 million. In both cases, attackers exploited flaws in the protocols' logic or pricing mechanisms, not a compromise of the blockchain infrastructure itself.
A similar scenario was observed during the attack on Summer.fi, where a hacker stole about $6 million by manipulating the protocol's accounting logic using a $65.4 million flash loan. Another approximately $9.05 million was lost by Bonzo Lend users due to an error in verifying the Supra price oracle.
Precisely such vulnerabilities could be one area where advanced AI models can strengthen the protection of crypto infrastructure: they can analyze large codebases, search for atypical exploitation scenarios, and help developers identify problems before they are exploited by attackers.








