More than thirty Bitcoin companies, including Coinbase, Block and BitGo, have signed an open letter asking major AI labs to grant open source security researchers early access to their most advanced models. The move highlights that attackers are already leveraging AI to identify vulnerabilities, leaving defenders at a disadvantage.
🔑 Key takeaways
- 30+ Bitcoin and crypto firms signed an open letter coordinated by the Bitcoin Policy Institute
- They request early access to the most powerful AI models for open source maintainers
- Timing coincides with a critical BTCPay flaw already exploited by attackers
- Stakes: over $1 trillion in value backed by Bitcoin alone
- An Ethereum libp2p flaw (CVE-2026-34219) was also discovered by an AI agent in July
An open letter to rebalance the attack-defense equation
The letter, organized by the Bitcoin Policy Institute (BPI) and published this week, brings together signatures from Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, Exodus as well as non-profit development funds Brink, Chaincode and Btrust.
The core complaint is clear: Bitcoin Core developers — the small group maintaining the software running the network — cannot access the programs that labs run for their trusted security partners. When they turn to public models, the safety filters designed to prevent users from writing malicious code also block efforts to find flaws before criminals do. They are then forced to rely on open-weight models, freely downloadable but generally less capable.
« Over $1 trillion in value is backed by Bitcoin alone, meaning a serious vulnerability in the financial infrastructure can put users’ savings at risk. »
Bitcoin Policy Institute, open letter

Five concrete demands to AI labs
Signatories formulate five specific requests to AI labs, according to CoinDesk and Crypto.news:
- Early access to the most powerful cyber models, including before public release
- Compute budget sufficient to run meaningful reviews
- Secure environments to examine private code
- Eligibility for small independent maintainers, not only for large companies
- Direct line with labs’ security teams to report findings
Recent attacks confirm the urgency
The timing of the letter is no accident. BTCPay Server, a signatory, disclosed a critical flaw last week that attackers had already exploited to drain Lightning nodes (second-layer payment channels) belonging to merchants. Foundation, the hardware wallet maker also among signatories, lost its own node in the attack.
BTCPay wrote afterward that AI is changing the balance between attackers and defenders, and that models make it faster and cheaper to search for weaknesses in large codebases. A volunteer group called Bitcoin Red Team started pointing AI models at Bitcoin codebases this month and filed thousands of findings across hundreds of projects, including the report that produced the BTCPay patch.
Bitcoin Core developers have meanwhile fixed several other vulnerabilities in recent months. In June, Bitcoin Core 31.1rc1 patched a privacy issue involving PrivateBroadcast that could expose a user’s IP address under certain network conditions. The release candidate also contained changes covering wallet accuracy, networking, blockchain validation and MuSig2 security (multi-party signature protocol).
| Vulnerability | Component | Impact | Affected period |
|---|---|---|---|
| CVE-2024-52911 | Bitcoin Core | Remote node crash | Versions 0.14.0 to 29.0 |
| BTCPay Server flaw | Lightning Network | Merchant node drain | Active exploit in 2026 |
| CVE-2026-34219 | Ethereum libp2p | Peer-to-peer network flaw | Disclosed July 2026 |
A deeper trend: AI at the heart of crypto cyberattacks
The Bitcoin Policy Institute said it received multiple independent reports from open source maintainers about sophisticated actors using advanced AI capabilities to run attacks. Some of the activity potentially involved foreign adversaries, according to the institute.
The Ethereum Foundation study published in July showed that coordinated AI agents could discover real vulnerabilities in software used by Ethereum, including the libp2p flaw (peer-to-peer networking library) later disclosed as CVE-2026-34219. The Foundation’s protocol security team said the hardest part was distinguishing real vulnerability reports from convincing false positives generated by AI.
Hack loss figures give a sense of the scale of the problem. According to DefiLlama, more than $634 million was stolen from crypto platforms in April, the highest monthly losses since the Bybit hack. Two attacks accounted for the bulk: Drift Protocol lost approximately $285 million, while an exploit involving KelpDAO resulted in losses of about $292 million. Over the past decade, more than $17 billion has been stolen across 518 crypto hack incidents.
« The next three to four years could be critical for crypto cybersecurity while defensive teams work to use the same AI capabilities to produce more secure codebases. »
Mitchell Amador, CEO of Immunefi
Conclusion: a race against the clock for maintainers
This open letter marks a turning point in how cyber risk to decentralized infrastructure is perceived. For years, open source developers relied on manual audits and bug bounty programs (rewards for flaw discovery). The arrival of generative AI models used by attackers changes the equation: the speed of vulnerability discovery is no longer constrained by human resources, but by tool access.
The response from AI labs will be decisive. If the most capable models remain inaccessible to Bitcoin Core maintainers and open source projects, the gap with already well-equipped attackers will widen. Conversely, structured collaboration — as proposed by the letter — could turn AI into an ally of the defense. The coming months, with the likely arrival of new model generations, will be critical to assess whether the crypto ecosystem is taking the measure of this new threat.
Sources
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

