Bitcoin Companies Ask AI Labs for Better Security Access
Coinbase, Block, and BitGo want AI labs to give open-source security researchers earlier access to powerful models. The call comes after recent Bitcoin and Lightning vulnerabilities.

Key Takeaways
- More than three dozen Bitcoin and crypto companies are asking AI labs to give open-source security researchers earlier access to powerful models.
- Signers say Bitcoin Core developers now have weaker tools than attackers and also want more compute, secure environments, and direct reporting channels.
- The letter follows recent Bitcoin security incidents and the growing use of AI to find vulnerabilities faster in codebases.
More than three dozen Bitcoin and crypto companies are asking the biggest AI labs to give open-source security researchers earlier access to their most powerful models. According to the signers, the people who have to defend a trillion-dollar infrastructure are working with weaker tools than the attackers targeting it.
The letter, organized by the Bitcoin Policy Institute and published earlier this week, was signed by Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, and Exodus, among others. Nonprofit development funds like Brink, Chaincode, and Btrust are also on the list. The core of their complaint is that Bitcoin Core developers, the small group that maintains the software the network runs on, cannot get into the programs that labs do open up for trusted security partners.
Security Tools Are Falling Behind
If they turn to publicly available models instead, the letter says they run into safety filters meant to block malware. Those same filters make it harder to find vulnerabilities before criminals do. As a result, researchers are often left relying on open-weight models, which are free to download but usually less capable.
The signers are therefore asking for five things: early access to the strongest cyber-capable models, including before public release, enough compute to carry out serious reviews, secure environments to inspect private code, access for small and independent maintainers, and a direct line to the labs' security teams to report findings.
Attackers Have No Brake Pedal
According to the letter, labs and a handful of partners see new offensive capabilities months before the rest of the market, while those capabilities still spread widely through public models, stolen access to corporate environments, and purpose-built hacking tools. That points to a broader reality in cybersecurity: the same AI that helps defenders can also be used to make attacks faster and more scalable.
That tension is also playing out around the crypto sector itself. In June, for example, OpenAI launched its Daybreak cybersecurity initiative with two access tiers for defensive and more advanced tasks, while other labs are testing models for misuse and resilience. At the same time, recent research shows that frontier models can sometimes independently find serious zero-days, raising the bar for defenders even further.
Why This Matters for Bitcoin
The timing of the letter stands out because two signers have already seen the practical side of that debate in recent weeks. BTCPay Server reported last week a critical bug that had already been exploited to drain merchants' Lightning nodes. Foundation, the maker of hardware wallets, also lost its own node in that attack.
BTCPay later wrote that AI is changing the balance between attackers and defenders because models make it faster and cheaper to scan large codebases for weak spots. A volunteer group, the Bitcoin Red Team, has already put AI models to work on Bitcoin codebases this month and submitted thousands of reports across hundreds of projects. So the companies' request is not just theoretical, but directly tied to how Bitcoin software and the wallets around it are protected in practice.
The recent BTCPay flaw shows how quickly a vulnerability in payment infrastructure can lead to real losses. That makes the call to AI labs mainly a practical security issue for many Bitcoin companies.