Криптовалюты38436
Капитал. рынка$ 2.27T-1.14%
Объём 24ч$ 21.42B+42.6%
ДоминацияBTC56.60%-0.48%ETH9.94%-1.53%
ETH Gas0.12 Gwei
Cryptorank
/

Why Are Bitcoin Security Researchers Turning to Chinese AI?


Why Are Bitcoin Security Researchers Turning to Chinese AI?

Поделиться:

AI Обзор

A Bitcoin security researcher says OpenAI restricted his Trusted Access for Cyber use, forcing him to revert to Chinese open-source AI models while participating in Bitcoin Red Team, which reported 4,962 potential issues across 390 projects, including 720 high or critical findings in its first 29.8 hours. The dispute and the July 30 Coldcard firmware 4.0.1 exploit that led to about 1,816 BTC (~$116 million) stolen underline that AI-driven vulnerability discovery, patch validation and crypto security are becoming contested resources that could hinder defender capabilities and threaten crypto adoption.

Медвежий

Рынки предсказаний

Что в фокусе у трейдеров?

Смотреть аналитику →
Prediction Banner

A Bitcoin security researcher says restrictions on OpenAI’s advanced cybersecurity tools forced him back to using Chinese open-source AI models.

AnchorWatch CEO Rob Hamilton, who is involved with the volunteer Bitcoin Red Team initiative, said on X that he started integrating OpenAI’s Trusted Access for Cyber capabilities into the group’s security work before discovering that his access had been restricted.

Hamilton said the decision would force him to return to Chinese open-source models to continue examining Bitcoin-related software. “It absolutely guts me as a patriotic American,” Hamilton said.

Bitcoin Red Team is using AI to hunt vulnerabilities

Hamilton’s work is part of Bitcoin Red Team, which is a volunteer security initiative combining AI-powered code analysis with human review to examine open-source software across the Bitcoin ecosystem. The scale of the project has grown quite a bit.

During its first 29.8 hours of operation, the group reported finding 4,962 potential issues across 390 Bitcoin-related projects. Of those findings, 720 were classified as high or critical severity, while around 21.4% had been reproduced at that stage.

Those figures should not be interpreted as 4,962 confirmed vulnerabilities. Many AI-generated findings still need to be reproduced and manually validated before they can be considered genuine security flaws.

However, the volume proves exactly why security researchers are becoming interested in using frontier AI models for code auditing. Instead of manually reviewing every line of hundreds of repositories, AI systems can explore unfamiliar codebases, identify suspicious paths and prioritize areas that deserve human attention.

Hamilton said losing access also prevented him from continuing investigations into whether fixes made to affected codebases were sufficient and whether related vulnerabilities remained undiscovered.

OpenAI built Trusted Access for exactly this type of work

The situation is especially interesting because OpenAI describes Trusted Access for Cyber as a framework that is designed to give verified security researchers greater freedom when performing legitimate cybersecurity work.

OpenAI says approved users receive fewer classifier-based refusals when conducting activities including vulnerability discovery, vulnerability triage, malware analysis, binary reverse engineering, detection engineering and patch validation.

The company also offers GPT-5.5-Cyber under more restrictive access conditions for specialized work like authorized red teaming, penetration testing and controlled exploit validation.

OpenAI argues that stronger models require tighter identity verification, monitoring and authorization because the same capabilities that allow researchers to find vulnerabilities can also enable malicious actors to exploit them. Hamilton’s experience, however, shed some light on the challenge of drawing that boundary in practice.

“Black hats will not hit these issues. The white hats will,” Hamilton said, arguing that defenders who follow access rules risk being restricted while attackers can simply use models that impose fewer limitations.

Coldcard hack puts Bitcoin security under pressure

The Bitcoin Red Team effort gained even more urgency after the major Coldcard hardware wallet exploit was discovered in July.

Blockchain intelligence firm TRM Labs estimates approximately 1,816 BTC, worth around $116 million, was stolen from more than 5,200 addresses during four waves of theft beginning July 30. The total is still preliminary.

Researchers traced the incident to firmware version 4.0.1, released in 2021. A build configuration problem caused some wallets to rely on weaker software-generated randomness when creating wallet seeds rather than the intended hardware entropy source. That potentially allowed attackers to brute-force affected private keys remotely.

Importantly, simply updating vulnerable devices does not secure wallets whose seeds were generated using the affected firmware. Those users need to generate new seeds and move their Bitcoin to new addresses.

The incident made it very clear that even hardware wallets and cold-storage systems can contain software vulnerabilities with potentially catastrophic consequences.

AI access could become a cybersecurity battleground

The dispute surrounding Hamilton points to a bigger issue that may become more important as AI models improve. Frontier models are becoming powerful enough to assist with vulnerability discovery, exploit validation and large-scale code analysis. OpenAI itself says these systems can help defenders understand unfamiliar code, trace root causes, analyze attack paths and review patches considerably faster.

But restricting those capabilities creates a difficult balance. Too little control could give attackers powerful automated hacking tools. Too much control could leave legitimate researchers working with weaker systems while malicious actors turn to unrestricted or locally hosted alternatives.

For the Bitcoin ecosystem, the question may no longer simply be whether AI should be used to audit open-source infrastructure. It may be who gets access to the most capable AI security tools — and whether defenders can get them quickly enough.

Читать материал на Coinpaper

В этой новости

Монеты


Фонды

Рынки предсказаний

Что в фокусе у трейдеров?

Смотреть аналитику →
Prediction Banner

Поделиться:

В этой новости

Монеты


Фонды

Рынки предсказаний

Что в фокусе у трейдеров?

Смотреть аналитику →
Prediction Banner

Поделиться:

Читать больше

The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It

The Korean Crypto Laundering Method Behind $6.4 Billion, and Why Police Struggle to Stop It

In Brief A cross-border technique called Hwanchigi sits behind 90% of South Korea's ...
Brazil Targets Crypto Fraud With 24-Hour Hold on Transfers Over $10K

Brazil Targets Crypto Fraud With 24-Hour Hold on Transfers Over $10K

Brazil will require 24-hour holds on some crypto transfers over $10,000 to self-custo...