Bitcoin Security Researchers Say Restricted U.S. AI Models Are Falling Behind Chinese Open Models

Bitcoin Security Researchers Say Restricted U.S. AI Models Are Falling Behind Chinese Open Models

N
News Editor
2026-08-13 16:18:45
Bitcoin security researchers, company founders, and policy advocates are publicly warning that restrictions on leading U.S. AI systems are making legitimate defensive cybersecurity work harder, while Chinese open-source models are producing usable results. Rob Hamilton of AnchorWatch said OpenAI blocked him from analyzing a codebase he had already responsibly disclosed, even after he joined the company’s trusted cyber program and had completed KYC months earlier. He later said he was cut off again within 19 minutes after receiving access to OpenAI’s Daybreak Blue cyber model. Francis Pouliot of Bull Bitcoin said Chinese open models helped identify and patch a money-stealing exploit in a project he was auditing, while American models he pays for refused to review the same patch. Similar complaints came from Bitcoin Core contributor PortlandHODL and Galaxy research head Alex Thorn, who backed a Bitcoin Policy Institute open letter calling for trusted access to frontier AI models for qualified open-source defenders. Published on August 10 and signed by more than 70 digital-asset organizations, the letter asks AI labs for early access to cyber-capable systems, enough compute, secure code-review environments, and direct contact with lab security teams. The pressure intensified after a Coldcard firmware flaw, exploited from July 30, led to the theft of well over $100 million in bitcoin. Since then, the volunteer Bitcoin Red Team says it has scanned 501 projects and logged 7,958 findings, including 1,280 high or critical issues, with most compute spend going to Chinese open-weight models.

Bitcoin company leaders and open-source developers are warning that Chinese AI models are outperforming restricted U.S. frontier systems in defensive cybersecurity work, pushing researchers to rely on them to help secure critical Bitcoin infrastructure.

Bitcoin Security Researchers Say Restricted U.S. AI Models Are Falling Behind Chinese Open Models 2

Rob Hamilton, CEO of Bitcoin self-custody insurance company AnchorWatch, said American AI restrictions have become a serious obstacle. After joining OpenAI’s trusted cyber program — despite having completed KYC months earlier — he said he was blocked from continuing analysis on a codebase he had already responsibly disclosed.

Hamilton wrote: 「It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure. Black hats will not hit these issues. The white hats will.」

Days later, he said he gained access to OpenAI’s Daybreak Blue cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.

Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation in blunt terms. He posted: 「I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin.」

He added: 「USA AI industry is completely cooked if they don’t change this path,」 and followed that with 「Open-source Chinese LLMs. [orange heart emoji],」 saying open Chinese models such as Kimi K3 are actually helping Bitcoin-related security work.

In a follow-up, Pouliot said a Chinese open-source model found a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. The American models he pays for, he said, refused to review that same patch.

PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, also pointed to the performance gap. He wrote: 「US-based Frontier AI Model ‘You’re absolutely right!’ Chinese Open Model ‘78 critical vulnerabilities found.’ The implications of this are unfathomable.」

In another post, he said he felt he was 「basically asking Xi to not get my software hacked at this point,」 and called on OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.

Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter that called for trusted access to frontier models for open-source defenders. Thorn wrote: 「Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks. RED TEAM NEEDS THE MODELS.」

Bitcoin Policy Institute letter seeks trusted access

On August 10, the Bitcoin Policy Institute, a policy think tank focused on Bitcoin and, more recently, AI, published an open letter signed by more than 70 organizations across the digital-asset industry, including major custodians, exchanges, mining companies, and open-source development groups.

The letter asks frontier AI labs to set up clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails are leaving legitimate security researchers without access to the strongest models, forcing them onto less capable open-weight alternatives while sophisticated attackers face no comparable limits.

The signatories asked for early access to cyber-capable models, enough compute, secure environments for code review, and direct communication channels with lab security teams. They said frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.

These comments point to a wider pattern described by Bitcoin security researchers: U.S. models from OpenAI and Anthropic often refuse or restrict legitimate defensive work, including for users who were supposed to have explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results.

The report also said concerns about Chinese hosting infrastructure becoming an attack vector can be reduced because the models are open source and can be run in American-hosted data centers. If this trend continues, it could pressure the U.S. AI market.

Coldcard exploit led to a broader security push

Cybersecurity pressure inside the Bitcoin industry intensified after a firmware flaw in Coldcard hardware wallets began to be exploited on July 30. According to the report, the flaw led to the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine then published an urgent advisory titled 「COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED」 urging affected users to move funds.

In response, a volunteer effort called the Bitcoin Red Team was formed, led by open-source developer Calle and Rob Hamilton. Calle is the creator of Cashu and the developer behind the Android version of Bitchat.

The group carried out large-scale AI-assisted audits of Bitcoin open-source repositories. The report said Kimi K3 became the primary workhorse, alongside limited access to Western systems. Earlier Bitcoin Magazine coverage said the campaign produced thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.

By August 8, after more than 100 hours of work involving dozens of contributors, the team said it had scanned 501 projects and produced 7,958 findings. Of those, 1,280 were rated high or critical severity. Most compute spending, the report said, still went to Chinese open-weight models.

What the red-team campaign says about open-source security

Most recently, Calle shared lessons from the intensive red-team period. He said the effort has now essentially completed a basic scan of nearly the entire Bitcoin open-source landscape, and that much of the low-hanging fruit has already been exhausted.

He also said maintainers across projects have validated many of the critical and high-severity reports. Response times vary widely from project to project, and he described that as a signal of broader project health.

One of the main lessons, he said, is that every project needs its own permanent AI audit pipeline going forward. Projects that started this type of review months earlier are in a much stronger position today. Repositories without active maintenance, he said, should be treated as likely broken and unreliable.

Calle also argued that the human-only era of open-source security review is over. Verification is now effectively free, he said, and information overload needs to be handled with AI rather than complaints about PR slop.

At the same time, he said multiple concurrent and diverse human approaches remain the strongest way to find vulnerabilities, and outside red-teaming will probably remain necessary for the long term.

Calle repeatedly stressed another point: developers should stop writing security-critical code in C. In a follow-up post, he wrote: 「we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.」

The article said Bitcoin is the first major open-source ecosystem to face this collision between accumulated human-written code and frontier AI capability. The rest of the software world is expected to run into the same problem.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.