Bitcoin firms ask AI labs for same tools attackers already have

Bitcoin firms ask AI labs for same tools attackers already have

Tech

Coinbase, Block, BitGo and dozens of others signed a letter arguing that safety guardrails on frontier models are blocking legitimate security work while adversaries face no such limits.

By Shaurya Malwa

Updated Published

2min read

Share this article

Glasses in front of monitors with code (Kevin Ku/Unsplash)

Summary

More than three dozen bitcoin and crypto companies have asked the largest AI labs to give open-source security researchers early access to their most capable models, arguing that the people defending a trillion dollars of infrastructure are working with weaker tools than those attacking it.

The letter, organised by the Bitcoin Policy Institute and published earlier this week, is signed by Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, Exodus and others, alongside nonprofit developer funds including Brink, Chaincode and Btrust.

Its central complaint is that Bitcoin Core developers, the small group maintaining the software that runs the network, cannot access the programs’ labs run for trusted security partners.

When they turn to publicly available models instead, the safety filters designed to stop people from writing malware also block efforts to find flaws before criminals do.

That leaves them on open-weight models, which can be freely downloaded and are generally less capable.

Attackers face none of those constraints. The letter said the labs and a handful of partners can see new offensive capabilities months before anyone else. In contrast, those capabilities spread anyway through public models, stolen access to corporate systems and purpose-built hacking tools.

The signatories are asking for five things: Early access to the strongest cyber-capable models, including before public release, enough computing budget to run meaningful reviews, secure environments for examining private code, eligibility for small and independent maintainers rather than only large firms, and a direct line to lab security teams for reporting what they find.

The timing is not accidental. Two of the signatories have spent the past fortnight demonstrating both halves of the argument.

BTCPay Server, which signed the letter, disclosed a critical flaw last week that attackers had already exploited to drain Lightning nodes belonging to merchants. Foundation, the hardware wallet maker, also signed, and lost its own node in that attack. BTCPay wrote afterwards that AI is changing the balance between attackers and defenders, and that models make it faster and cheaper to search large codebases for weaknesses.

Defenders found the flaw itself. A volunteer group calling itself the Bitcoin Red Team began pointing AI models at bitcoin codebases this month and has filed thousands of findings across hundreds of projects, including the report that produced BTCPay’s patch.


 

Leave a Reply

Your email address will not be published. Required fields are marked *