Bitcoin and other open-source financial infrastructure developers could find themselves at a growing disadvantage against cyber attackers if they cannot access the most advanced artificial intelligence models, according to the Bitcoin Policy Institute.
In an open letter published Monday, the Bitcoin Policy Institute, or BPI, joined several major crypto companies and industry organizations in calling on leading AI developers to create trusted-access programs for qualified open-source security researchers.
The group argues that frontier AI models are becoming increasingly useful for reviewing large codebases, finding vulnerabilities and speeding up security research. But those same capabilities can also help sophisticated attackers identify weaknesses faster.
According to BPI, the problem is that legitimate developers may sometimes be blocked from advanced cybersecurity capabilities because of safety restrictions placed on publicly available AI models.
That could leave the people responsible for protecting critical open-source financial systems using weaker tools while attackers find other ways to access more capable technology.
Bitcoin developers want trusted access to advanced AI models
The proposal does not ask AI companies to remove security restrictions for everyone.
Instead, BPI wants frontier AI labs to establish or expand controlled programs that give vetted developers and cybersecurity researchers greater access to powerful AI capabilities.
The organization said qualified defenders of open-source financial infrastructure should be treated similarly to security researchers already allowed to use advanced cyber tools under specialized access programs.
Such access could help Bitcoin developers review software more efficiently, discover vulnerabilities earlier and fix security problems before attackers can exploit them.
The concern is particularly significant because open-source financial systems protect enormous amounts of value.
BPI noted that Bitcoin alone secures more than $1 trillion. A serious software vulnerability could therefore affect exchanges, wallets, businesses and individual users around the world.
Among the organizations supporting the letter were Anchorage Digital, BitGo, Bitwise, Blockstream, Bull Bitcoin, Kraken, Ledger, MARA and Trezor. The African Bitcoin Institute also signed the request.
Recent Bitcoin Core bugs show why security research matters
Bitcoin Core developers have already dealt with several important security issues that demonstrate how critical early vulnerability detection can be.
In June, Bitcoin Core 31.1rc1 addressed a privacy issue involving PrivateBroadcast that could potentially expose a user’s IP address under certain network conditions.
The release candidate also introduced updates related to wallet accuracy, network behavior, blockchain validation and MuSig2 security.
Another significant vulnerability was disclosed a month earlier.
Tracked as CVE-2024-52911, the high-severity bug could allow miners to remotely crash some Bitcoin nodes.
The vulnerability affected Bitcoin Core versions released after 0.14.0 and before version 29.0.
Exploiting the flaw was not simple because an attacker would need to produce costly proof-of-work blocks. Still, the issue demonstrated how bugs in widely used financial software can create potentially serious risks.
Security researcher Cory Fields privately reported the vulnerability in 2024, allowing Bitcoin Core developers to address it before publicly disclosing the issue.
Bitcoin Core 29.0, released in April 2025, included the fix.
Frontier AI could give defenders a major security advantage
BPI believes advanced artificial intelligence could dramatically change cybersecurity research.
Modern AI systems can analyze large amounts of code, search for unusual behavior and help developers investigate technical issues much faster than traditional manual methods alone.
That could eventually make frontier AI one of the most useful defensive technologies available to software security teams.
However, the same capabilities can also work in the opposite direction.
Attackers can potentially use powerful models to search for exploitable weaknesses, automate parts of vulnerability research and reduce the amount of specialist knowledge or time required to launch attacks.
BPI said it has received several independent reports suggesting sophisticated actors are already using advanced AI capabilities to support ongoing cyberattacks.
Some of those actors may include foreign adversaries, according to the institute.
This is why the group believes security teams protecting important open-source infrastructure need access to comparable technology.
Rather than giving unrestricted access to everyone, BPI wants AI labs to verify qualified researchers before allowing them to use advanced cybersecurity capabilities.
Human researchers are still needed alongside AI
AI’s ability to discover software vulnerabilities is already being tested across the crypto industry.
An Ethereum Foundation study published in July found that coordinated AI agents were able to identify real security weaknesses in software used by Ethereum.
Among the findings was a vulnerability in libp2p that was later disclosed as CVE-2026-34219.
However, the study also highlighted one of the biggest challenges facing AI-powered security tools: false positives.
AI systems can generate reports that appear technically convincing but do not represent genuine vulnerabilities.
As a result, human researchers still need to reproduce findings, verify exploit conditions and determine whether an AI-generated security report represents a real threat.
That suggests AI is more likely to strengthen experienced security teams than completely replace them.
Crypto hacks continue to create pressure on developers
The push for better defensive tools comes as cryptocurrency platforms continue to suffer major security losses.
Data cited from DefiLlama showed that more than $634 million was stolen from crypto platforms during April 2026, making it the industry’s largest monthly loss since the Bybit hack.
Earlier data showed that more than $606 million had already been lost across 12 incidents during the first 18 days of April.
That figure was approximately 3.7 times higher than the $165.5 million stolen throughout the first quarter of 2026.
Two incidents were responsible for most of the losses recorded during that period.
Drift Protocol suffered losses of around $285 million, while an exploit involving KelpDAO resulted in losses of approximately $292 million.
Together, those incidents represented roughly 95% of the reported losses during the first 18 days of April.
The broader threat is also no longer limited to smart-contract vulnerabilities.
Private-key theft, phishing, compromised credentials, social engineering and infrastructure attacks have become increasingly important parts of the crypto security landscape.
By April, DefiLlama had tracked more than $17 billion in losses across 518 cryptocurrency hacking incidents over the previous decade.
AI could make attacks faster and easier to scale
Security researchers have repeatedly warned that artificial intelligence could lower the cost of launching sophisticated attacks.
AI-assisted phishing campaigns can generate highly convincing messages at scale, while deepfake tools can imitate executives, employees or trusted contacts.
Automated security systems may also help attackers inspect software and identify weaknesses faster than traditional manual research.
CertiK warned earlier this year that AI-assisted phishing, deepfakes and automated exploit tools were making attacks faster and more difficult to identify.
Cross-chain infrastructure and social engineering were also highlighted as major areas of concern.
For defenders, this creates pressure to adopt the same technologies attackers may be using.
If malicious actors can automate vulnerability discovery while legitimate developers remain limited to less capable AI models, the gap between offensive and defensive cybersecurity capabilities could widen.
Advanced AI is changing vulnerability discovery
The rapid improvement of frontier AI models has already changed expectations around software security.
Mitchell Amador, CEO of bug bounty platform Immunefi, previously described the arrival of highly capable models such as Claude Opus 4.8 and ChatGPT 5.5 as contributing to what he called a “vulnerability apocalypse” for the crypto industry.
His argument is that advanced AI dramatically increases the number of people and systems capable of finding software weaknesses.
That could create a difficult period for crypto cybersecurity while developers strengthen existing codebases and integrate AI into their defensive workflows.
Amador estimated that the next three to four years could be especially important, although wider use of crowdsourced security research could shorten the transition.
AI-based security tools had already begun appearing across the crypto industry before the latest generation of models arrived.
In an October 2025 interview, Amador said automated vulnerability detection should complement traditional security measures rather than replace them.
Those measures include professional audits, bug bounty programs, real-time monitoring and transaction firewalls.
At the time, he estimated that fewer than 10% of crypto projects were actively using AI-powered vulnerability detection tools.
Vitalik Buterin also sees a role for AI in software security
Ethereum co-founder Vitalik Buterin has also argued that AI could play a larger role in building secure software.
In May, Buterin discussed the potential of AI-assisted formal verification, a process that uses mathematical proofs to confirm that software behaves as intended.
He suggested that developers could eventually combine highly optimized code with machine-checked proofs of correctness.
Potential applications could include Ethereum’s consensus mechanisms, zero-knowledge systems and quantum-resistant cryptography.
However, Buterin also cautioned that formal verification cannot remove every possible source of software risk.
That reflects a broader theme emerging across crypto security: artificial intelligence can significantly strengthen security research, but human oversight remains essential.
For Bitcoin developers, the immediate concern is making sure trusted defenders can access tools powerful enough to keep pace with attackers.
As frontier AI models become increasingly capable of discovering weaknesses in complex software, the ability to use those systems may become an important part of protecting Bitcoin and other open-source financial infrastructure.




















































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































