Headline: Bitcoin groups urge AI labs to give vetted devs access to top models as attackers use AI to scale hacks A coalition of crypto firms and industry organizations is pressing frontier AI labs to create trusted-access pathways for developers who maintain Bitcoin and other open-source financial infrastructure. In an open letter published Monday, the Bitcoin Policy Institute (BPI) warned that without vetted access to the most capable AI models, defenders risk falling behind attackers who increasingly use advanced AI to discover and weaponize software flaws. Why this matters - Frontier AI systems can rapidly scan large codebases, suggest exploit paths and automate technical work that previously required deep specialist effort. Those same capabilities can accelerate both defensive audits and offensive reconnaissance. - Bitcoin alone secures more than $1 trillion in value, BPI noted, meaning a serious bug in open-source financial software could jeopardize vast amounts of user funds. - BPI says some open-source maintainers are already reporting sophisticated actors using advanced AI to sustain attacks — in some cases involving suspected foreign adversaries. What BPI is asking for Rather than stripping security controls from powerful models for everyone, signatories want AI companies to “establish or expand standing trusted-access programs for qualified defenders of open-source financial infrastructure.” Under the proposal, vetted security researchers and maintainers would get controlled access to capabilities normally restricted in public models so they can hunt for vulnerabilities at the same scale attackers now can. “Without dedicated access programs, defenders may lack the tools needed to keep pace with evolving threats to the infrastructure they maintain,” the letter said. Who backed the letter Major crypto companies and organizations joined the request, including Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, MARA, Kraken, Ledger, Trezor and the African Bitcoin Institute. Recent context: real vulnerabilities and rising losses The letter argues the access gap is urgent, pointing to recent Bitcoin Core fixes and high-severity bugs that had to be found and patched before exploitation. Examples cited: - June: Bitcoin Core 31.1rc1 fixed a PrivateBroadcast privacy issue that could reveal a user’s IP under some network conditions; the release also included fixes for wallet accuracy, networking, validation and MuSig2 security. - Earlier: a high-severity bug tracked as CVE-2024-52911 could let miners remotely crash certain nodes; security researcher Cory Fields privately reported the flaw before it was fixed in Bitcoin Core 29.0 (April 2025). The broader industry has also seen high-profile AI-driven research and stark loss figures: - July: An Ethereum Foundation study showed coordinated AI agents could surface genuine vulnerabilities in Ethereum code, including a libp2p flaw later disclosed as CVE-2026-34219. The Foundation stressed that human validation and reproducible proofs remain essential to separate true bugs from false positives. - DefiLlama data cited by BPI showed April 2026 saw over $634 million stolen from crypto platforms — the industry’s highest monthly loss since an earlier Bybit-related wave that helped push February 2025 losses to roughly $1.4 billion. Two April incidents alone — a roughly $285 million loss at Drift Protocol and about $292 million at KelpDAO — explained most of that month’s total. - Over the decade through April 2026, DefiLlama recorded more than $17 billion stolen in 518 crypto attacks, with a growing share from private-key leaks, phishing and credential theft alongside smart-contract exploits. AI as double-edged sword Security firms have warned that AI lowers the time and technical skill needed to find and exploit weaknesses. CertiK flagged AI-assisted phishing, deepfakes and automated exploit tools as making attacks faster and harder to detect, while cross-chain infrastructure and social engineering remain lucrative attack vectors. Some industry voices frame the moment as critical: Mitchell Amador, CEO of bug-bounty platform Immunefi, called the emergence of models such as Claude Opus 4.8 and ChatGPT 5.5 a driver of a “vulnerability apocalypse,” saying advanced models have shifted the attacker-defender balance. He predicted the next three to four years will be pivotal for crypto security, though wider use of crowdsourced defenses could compress that timeline. At the same time, defenders already see AI’s potential. Ethereum co-founder Vitalik Buterin has argued that AI-assisted formal verification could enable highly optimized code backed by machine-checked proofs, improving safety across consensus systems, zero-knowledge tech and cryptography — though formal methods can’t remove every risk. What the proposal would (and wouldn’t) do - Would: create standing, vetted programs giving qualified open-source financial maintainers access to restricted AI model capabilities for vulnerability discovery and defensive work. - Wouldn’t: ask AI developers to remove safeguards for all users. The aim is controlled, accountable access that mirrors other restricted cyber-defense programs. The coalition’s ask frames frontier AI not only as a growing threat vector but also potentially one of the most powerful defensive tools ever — if defenders can access it responsibly. With high-value infrastructure at stake and attackers racing to adopt automation, BPI and its signatories argue the window to rebalance tools and access is now. Read more AI-generated news on: undefined/news