Bitcoin developers risk falling behind attackers unless frontier AI labs grant them vetted access to the most capable models, the Bitcoin Policy Institute (BPI) warns in a new open letter. What BPI is asking for - The BPI and a coalition of crypto firms and organizations are urging leading AI labs to create or expand “trusted-access” programs that give qualified maintainers and security researchers of open-source financial infrastructure access to advanced AI capabilities that are otherwise restricted. - The request is not to remove safety controls for all users, the letter stresses; instead, it seeks controlled, vetted channels that let defenders use powerful tools while keeping them out of malicious hands. Why this matters now - Large-scale, frontier AI models can rapidly scan massive codebases, surface potential vulnerabilities and accelerate complex security analysis. Those same capabilities, however, can be leveraged by attackers to find weak spots faster than human teams can. - BPI argues that when frontier models block security-related queries or limit access to specific partner programs, open-source maintainers—like Bitcoin Core developers—are often forced to rely on weaker, open-weight models. That access gap could leave defenders trailing attackers at a time when the stakes are enormous: Bitcoin alone secures more than $1 trillion in value, and vulnerabilities in financial infrastructure put users’ savings at risk. Who signed on Major crypto firms and organizations backing the request include Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, MARA, Kraken, Ledger, Trezor and the African Bitcoin Institute. Concrete examples showing the threat and the need - Real-world bugs highlight what maintainers need to catch. In June, Bitcoin Core 31.1rc1 patched a privacy issue in PrivateBroadcast that could expose users’ IP addresses under certain network conditions, plus fixes touching wallet accuracy, networking, validation and MuSig2 security. - In an earlier case, a high-severity bug tracked as CVE‑2024‑52911—reported privately in 2024—could allow miners to remotely crash some nodes. The flaw affected versions after 0.14.0 and before 29.0; it required miners to produce costly proof-of-work blocks to trigger. The bug was fixed in Bitcoin Core 29.0 (April 2025). AI’s dual role: defensive force multiplier — and weapon - BPI calls frontier AI a disruptive force that is reshaping the economics of both cybersecurity research and cyber operations: tasks that once required lots of specialist human effort can now be accelerated by advanced models. That makes AI potentially one of the most powerful defensive technologies if accessible to defenders. - But the institute also says it has received multiple independent reports of sophisticated actors using advanced AI to sustain attacks, with some activity potentially tied to foreign adversaries. Industry precedents and limits - The Ethereum Foundation’s Protocol Security team ran an experiment in July showing coordinated AI agents could surface real vulnerabilities—one later disclosed as CVE‑2026‑34219 in libp2p. The Foundation cautioned that AI reports still need human validation to separate genuine bugs from convincing false positives and to produce reproducible proof. - Security firms warn AI is already shortening attack timelines. CertiK flagged in April that AI-assisted phishing, deepfakes and automated exploit tools are making attacks faster and harder to detect, while attackers continue to use cross-chain bugs, credential theft and social engineering. Recent industry losses underscore urgency - 2026 has seen heavy losses. DeFiLlama data cited in June showed more than $634 million stolen from crypto platforms in April—the highest monthly total since the Bybit incident that contributed to about $1.4 billion in losses in February 2025. - Early-April figures reported more than $606 million stolen across 12 incidents in the first 18 days. Two incidents dominated: Drift Protocol (~$285 million) and KelpDAO (~$292 million), accounting for about 95% of those early-April losses. - Over the prior decade, DeFiLlama had recorded over $17 billion lost in 518 incidents by April, with private-key leaks, phishing and credential theft increasingly common alongside protocol exploits. Voices from the field - Mitchell Amador, CEO of bug-bounty platform Immunefi, called the spread of cutting-edge models such as Claude Opus 4.8 and ChatGPT 5.5 a contributor to a “vulnerability apocalypse” for crypto, arguing the next three to four years will be critical as defenders race to build AI-enabled defenses. He noted widespread adoption of AI security tools could compress that timeline. - Ethereum co‑founder Vitalik Buterin has made a similar point about AI’s defensive potential, highlighting AI-assisted formal verification as a path to combine highly optimized software with machine-checked proofs—while acknowledging formal methods cannot eliminate all risk. What proponents want next - The proposed standing programs would vet open-source financial maintainers and vetted security researchers, grant them more capable model access for defense work, and keep other restrictions in place to prevent abuse. The goal: narrow the tools gap between attackers and defenders while preserving safeguards against malicious use. Bottom line As AI sharply raises both the power and speed of cyber reconnaissance and exploit development, BPI and several major crypto firms argue that defenders of the open financial stack need trusted, controlled access to frontier models to stay ahead. The open letter frames the debate as a pragmatic, safety-focused compromise: let defenders use the best tools under strict vetting, rather than leaving the field dominated by attackers or fully opening capabilities to everyone. Read more AI-generated news on: undefined/news