A coalition of more than 40 digital-asset organizations led by the Bitcoin Policy Institute is urging the world’s top AI labs to give vetted open‑source security researchers controlled access to “frontier” AI models — arguing that defenders need the same advanced tools attackers increasingly use. Why: AI is already changing the cyber threat landscape - Recent activity shows threat actors are using local and open-source AI models to automate malware, craft phishing, and analyze stolen data without sending queries to monitored cloud services. North Korea‑linked group Kimsuky has reportedly built local environments from tools such as Ollama, GPT4All and Msty to power these capabilities. - Locally run models evade the monitoring, usage controls and account suspensions that constrain commercial AI services. That asymmetry means restricting public access to powerful models doesn’t necessarily stop attackers — it can instead handicap researchers who need to test defenses against the same capabilities. What the coalition is asking for The open letter — announced by the Bitcoin Policy Institute in an Aug. 10 post and signed by a broad swath of the crypto ecosystem — requests a narrowly scoped, controlled program that would provide: - early access to frontier cybersecurity models (not unrestricted public release); - sufficient computing resources for realistic testing; - secure research environments; and - direct communication channels with AI labs’ security teams. The goal: let vetted researchers examine Bitcoin wallets, payment infrastructure and other open‑source software before attackers can exploit newly discovered weaknesses. Who signed on Supporters include major exchanges, custody and crypto infrastructure firms and developer groups, among them Block, Coinbase, Strategy, MARA, Galaxy, BitGo, Brink, OpenSats, Chaincode Labs, Spiral, Trezor, Unchained, Btrust and Fedi. No major AI lab had publicly committed to such a program at the time of writing. Concrete incidents that illustrate the risk - Coldcard firmware bug: A firmware build error reportedly weakened entropy used to generate seed phrases, shrinking key search space and enabling large wallet thefts without physical access. Galaxy Research put confirmed Coldcard thefts at about 1,596 BTC, with suspected additional losses possibly raising that figure to ~2,055 BTC. The flaw may have existed since 2021. - Kimsuky and local models: As noted, the use of local AI setups lets attackers develop and deploy tools offline, complicating detection and attribution. How AI can help defenders — and its limits The letter points to successful defensive uses of AI as proof of concept: - Bitcoin Red Team used AI‑assisted code review to flag 4,962 potential issues across 390 Bitcoin projects in under 30 hours; 720 were initially classed as high or critical, and more than one in five findings were reproducible when manually checked. These examples show frontier models can accelerate review of large codebases, but human experts are still required to verify, reproduce and safely disclose real vulnerabilities. Funding vs. technical access The call complements recent industry funding efforts aimed at beefing up Bitcoin security: - The Bitcoin Security Consortium (backed by Strategy, BlackRock, Coinbase and others) pledged $15 million over three years, initially focusing on post‑quantum cryptography. - Galaxy launched a separate $5 million fund for signature systems, wallet migration tools, audits and quantum‑resistant research. The coalition argues financial support alone isn’t enough — researchers also need technical access to advanced models and secure test environments. The wider context: rising losses Industry losses remain high: Immunefi reported roughly $110 million stolen in July, recording 164 incidents through Aug. 3, and projects that the number of hacks exceeding $1 million could reach a record 114 in 2026. What happens next The coalition is asking AI companies to augment monetary backing with responsible, restricted access that lets trusted defenders find and fix vulnerabilities before attackers weaponize AI. AI labs will have to balance that request against risks: verifying researcher credentials, supervising sensitive work, and preventing misuse of advanced cybersecurity models. If labs can craft robust vetting and containment measures, the move could shift the balance — giving open‑source defenders a real chance to keep pace with an evolving, AI‑enabled threat landscape. Read more AI-generated news on: undefined/news