Key Takeaways: Bitcoin security researchers are abandoning restricted American AI models for Chinese open-source alternatives that deliver confirmed results on critical infrastructure audits.
Key Takeaways: Bitcoin security researchers are abandoning restricted American AI models for Chinese open-source alternatives that deliver confirmed results on critical infrastructure audits.

Bitcoin security researchers are abandoning restricted American AI models for Chinese open-source alternatives that deliver confirmed results on critical infrastructure audits.
Chinese open-source AI models are outperforming restricted frontier systems from OpenAI and Anthropic on defensive cybersecurity, forcing Bitcoin researchers to rely on them after American models repeatedly blocked legitimate audits.
Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance firm, said he was blocked from further analysis on a codebase he had already responsibly disclosed, even after completing KYC months earlier. "It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure," he wrote. Days later, after gaining access to OpenAI's "Daybreak Blue" cyber model, he was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.
The Bitcoin Red Team, a volunteer effort led by open-source developer Calle and Hamilton, scanned 501 projects and produced 7,958 findings, of which 1,280 were rated high or critical severity. The majority of compute spend went to Chinese open-weight models like Kimi K3. The campaign followed a Coldcard hardware wallet firmware exploit that resulted in the theft of more than $100 million in bitcoin from seeds generated with insufficient entropy.
More than 70 organizations, including Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, and Exodus, signed a Bitcoin Policy Institute open letter calling on frontier AI labs to establish trusted-access programs for open-source defenders. The letter argues that current restrictions leave legitimate security researchers without access to the strongest models while sophisticated attackers face no such limits.
The volunteer effort, with spending covered largely by OpenSats, reported scanning 501 projects and producing 7,958 findings after more than 100 hours of work involving dozens of contributors. Maintainers across projects have validated many of the critical and high-severity reports, while response times from projects vary widely and serve as a signal of overall health.
Calle, creator of Cashu and the Android version of Bitchat, shared lessons from the intensive red-team period, noting that the effort has essentially completed a basic scan of virtually the entire Bitcoin open-source codebase. He warned that the human-only era of open-source security review is over, and that developers should stop writing security-critical code in C. "We're finding memory-safety vulnerabilities in C projects that are prevented by default in many other languages," he wrote. "In the past, finding a simple buffer overflow wasn't enough. You'd need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that's a single prompt."
Francis Pouliot, founder of Bull Bitcoin, detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked the American models he pays for to review the same patch, they refused. PortlandHODL, a Bitcoin Core contributor, highlighted the gap: "US-based Frontier AI Model — 'You're absolutely right!' Chinese Open Model — '78 critical vulnerabilities found.'"
The Bitcoin Policy Institute open letter, published August 10, calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code, and direct channels with lab security teams.
The stakes are concrete: BTCPay Server, a signatory, disclosed a critical flaw last week that attackers had already exploited to drain Lightning nodes belonging to merchants. Foundation, the hardware wallet maker, also signed and lost its own node in that attack.
Alex Thorn, Head of Firmwide Research at Galaxy, signed the letter. "Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks," he wrote. "RED TEAM NEEDS THE MODELS."
Concerns about hosting infrastructure of Chinese models being an attack vector can be mitigated since they are open source and can be run on American-hosted data centers, a trend that is likely to threaten the U.S. AI market if it continues.
The competitive dynamics carry direct implications for the U.S. AI sector. If Chinese open-weight models continue to deliver superior results on security-critical workloads while American frontier labs restrict access, enterprise and infrastructure customers may shift procurement toward open-source alternatives. Bitcoin was the first major open-source project to confront this collision between accumulated human code and frontier AI capability — the rest of the software world is expected to follow.
This article is for informational purposes only and does not constitute investment advice.