More than forty cryptocurrency companies are urging leading artificial intelligence labs to allow approved Bitcoin security experts to use advanced models that are already in the hands of hackers. This request is coordinated by the Bitcoin Policy Institute (BPI) and explains that access to technologies, including from OpenAI and Anthropic, is essential to protect software that safeguards assets worth over $1 trillion.
At the core of this premise lies a risky assumption that remains unclear. If both criminals and researchers have access to the same technology, what does this mean for Bitcoin's security? The letter from BPI acknowledges that the technology is dual-use, as models that allow a programmer to search for issues in a large system also enable a malicious actor to do the same.
The Gap This Letter Seeks to Close
According to BPI, it is unclear who will be left with weaker tools. The letter states that when advanced systems ignore security requests or block certain key functions with programs that bypass the use of any open financial architecture, developers are forced to resort to weaker open-source models. Malicious actors are not subject to such restrictions.
The letter does not call for labs to remove security measures for everyone. Rather, the signatories would like to see "ongoing trusted access programs for qualified defenders of open-source financial infrastructure," where researchers undergo an evaluation process before gaining access to things forbidden to the public. The idea is that this would give Bitcoin developers a new status, similar to that of security specialists tackling complex cybercrime.
Sophisticated Malicious Actors Use Advanced AI to Conduct Attacks
BPI reported receiving various reports from open-source software developers indicating the presence of sophisticated malicious actors using advanced AI to conduct attacks, with some of these actors possibly being foreign adversaries. As previously reported by Cryptopolitan, attacks on Bitcoin infrastructure are a constant threat, not a one-off event.
Those responsible for defense speak of an uneven fight. A Bitcoin core developer wrote on X (formerly Twitter) on August 13th that the work led to some discoveries, adding that this represents a "massive collision of decades of human open-source development with two weeks of Kimi K3's work." Kimi is developed by the Chinese AI lab Moonshot, making the connection even more striking: the same class of models being tested for defense is also at the center of the broader U.S.-China AI race.
Here is Where the U.S.-China Front Comes Into Play
The availability question is tied to growing competition. Chinese models "now lag behind U.S. ones by months, not years," said CSIS analyst Yasi Atalan in July, citing a government study showing that DeepSeek V4-Pro—the best Chinese open-source model—lags about eight months behind U.S. leaders.
Data published in the 2026 Stanford AI Index shows that by 2025, the U.S. developed 59 important models, while China developed 35, but leads the world in research volume and patents.
This matters for Bitcoin, as a defensive advantage based on restricted U.S. models weakens as strong competitors with broad capabilities spread. There are precedents of real bugs found with AI: the Ethereum Foundation used coordinated AI agents in a study to identify genuine vulnerabilities, including one in libp2p later identified as CVE-2026-34219.
Whether this capability will be more on the side of defenders or attackers remains an open question that cannot be resolved on its own. SlowMist recorded 182 blockchain security incidents in the first half of 2026, with estimated losses of approximately $956 million, and warned that AI is lowering the barrier for automated attacks and social engineering.
TRM Labs provides another useful comparison: a total of 207 security incidents with losses of $972 million were recorded in the first half of 2026. This can be a great addition to the methodology, illustrating how different security companies count incidents, and while their conclusions differ, both companies show the same trend: high frequency/low loss.
I gained a ton of new knowledge about bitcoin 🟥 that I'd like to share without making vague posts. But here's what I learned, anon:
— calle 🟥 (@callebtc) August 13, 2026
– We are experiencing a massive collision of decades of human open-source development and two weeks of Kimi K3's work (this is not good)
– everything...
Why Are Arms Race Concerns Not Hypothetical?
SlowMist's data validates the request. In the first half of 2026, there were 182 incidents with losses of about $956 million, compared to 121 incidents with losses of $2.373 billion in the same period of 2025.

SlowMist's data is well-supported by sources: 182 incidents with about $956 million in losses in H1 2026, compared to 121 incidents with $2.373 billion in H1 2025.

SlowMist recorded an increase in the number of incidents despite a sharp drop in total losses compared to H1 2025. The flip side is loss concentration: $2.373 billion in H1 2025 shrunk to about $956 million in H1 2026, despite a 50% increase in the number of incidents.

According to SlowMist data, 182 security incidents cost the crypto industry approximately $956 million in the first half of 2026. The number of incidents increased from 121 the year before, despite a sharp decline in losses. The next question facing the industry is whether incorporating advanced AI into defense systems can accelerate this trend—reducing the severity of attacks even if AI makes attacks faster and more numerous. Beyond this chilling point, here is another prophetic thought:
"Sometimes the old must be burned for the new to grow on healthy soil" – Calle








