Bitcoin company leaders and open-source developers are warning that Chinese AI models are outperforming restricted U.S. frontier systems in defensive cybersecurity work, pushing researchers to rely on them to help secure critical Bitcoin infrastructure.

Rob Hamilton, CEO of Bitcoin self-custody insurance company AnchorWatch, said American AI restrictions have become a serious obstacle. After joining OpenAI’s trusted cyber program — despite having completed KYC months earlier — he said he was blocked from continuing analysis on a codebase he had already responsibly disclosed.
Hamilton wrote: 「It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure. Black hats will not hit these issues. The white hats will.」
Days later, he said he gained access to OpenAI’s Daybreak Blue cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.
Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation in blunt terms. He posted: 「I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin.」
He added: 「USA AI industry is completely cooked if they don’t change this path,」 and followed that with 「Open-source Chinese LLMs. [orange heart emoji],」 saying open Chinese models such as Kimi K3 are actually helping Bitcoin-related security work.
In a follow-up, Pouliot said a Chinese open-source model found a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. The American models he pays for, he said, refused to review that same patch.
PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, also pointed to the performance gap. He wrote: 「US-based Frontier AI Model ‘You’re absolutely right!’ Chinese Open Model ‘78 critical vulnerabilities found.’ The implications of this are unfathomable.」
In another post, he said he felt he was 「basically asking Xi to not get my software hacked at this point,」 and called on OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.
Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter that called for trusted access to frontier models for open-source defenders. Thorn wrote: 「Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks. RED TEAM NEEDS THE MODELS.」
Bitcoin Policy Institute letter seeks trusted access
On August 10, the Bitcoin Policy Institute, a policy think tank focused on Bitcoin and, more recently, AI, published an open letter signed by more than 70 organizations across the digital-asset industry, including major custodians, exchanges, mining companies, and open-source development groups.
The letter asks frontier AI labs to set up clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails are leaving legitimate security researchers without access to the strongest models, forcing them onto less capable open-weight alternatives while sophisticated attackers face no comparable limits.
The signatories asked for early access to cyber-capable models, enough compute, secure environments for code review, and direct communication channels with lab security teams. They said frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.
These comments point to a wider pattern described by Bitcoin security researchers: U.S. models from OpenAI and Anthropic often refuse or restrict legitimate defensive work, including for users who were supposed to have explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results.
The report also said concerns about Chinese hosting infrastructure becoming an attack vector can be reduced because the models are open source and can be run in American-hosted data centers. If this trend continues, it could pressure the U.S. AI market.
Coldcard exploit led to a broader security push
Cybersecurity pressure inside the Bitcoin industry intensified after a firmware flaw in Coldcard hardware wallets began to be exploited on July 30. According to the report, the flaw led to the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine then published an urgent advisory titled 「COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED」 urging affected users to move funds.
In response, a volunteer effort called the Bitcoin Red Team was formed, led by open-source developer Calle and Rob Hamilton. Calle is the creator of Cashu and the developer behind the Android version of Bitchat.
The group carried out large-scale AI-assisted audits of Bitcoin open-source repositories. The report said Kimi K3 became the primary workhorse, alongside limited access to Western systems. Earlier Bitcoin Magazine coverage said the campaign produced thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.
By August 8, after more than 100 hours of work involving dozens of contributors, the team said it had scanned 501 projects and produced 7,958 findings. Of those, 1,280 were rated high or critical severity. Most compute spending, the report said, still went to Chinese open-weight models.
What the red-team campaign says about open-source security
Most recently, Calle shared lessons from the intensive red-team period. He said the effort has now essentially completed a basic scan of nearly the entire Bitcoin open-source landscape, and that much of the low-hanging fruit has already been exhausted.
He also said maintainers across projects have validated many of the critical and high-severity reports. Response times vary widely from project to project, and he described that as a signal of broader project health.
One of the main lessons, he said, is that every project needs its own permanent AI audit pipeline going forward. Projects that started this type of review months earlier are in a much stronger position today. Repositories without active maintenance, he said, should be treated as likely broken and unreliable.
Calle also argued that the human-only era of open-source security review is over. Verification is now effectively free, he said, and information overload needs to be handled with AI rather than complaints about PR slop.
At the same time, he said multiple concurrent and diverse human approaches remain the strongest way to find vulnerabilities, and outside red-teaming will probably remain necessary for the long term.
Calle repeatedly stressed another point: developers should stop writing security-critical code in C. In a follow-up post, he wrote: 「we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.」
The article said Bitcoin is the first major open-source ecosystem to face this collision between accumulated human-written code and frontier AI capability. The rest of the software world is expected to run into the same problem.


