Major crypto firms are urging AI labs to grant vetted security researchers greater access to advanced models, warning that current restrictions may leave digital asset infrastructure exposed to evolving cyber threats
Coinbase, Blockstream, and Strategy are among more than 40 organizations supporting a new initiative to expand access to advanced artificial intelligence models for qualified security researchers in the cryptocurrency sector. The campaign, led by the Bitcoin Policy Institute (BPI), calls on leading AI labs to provide trusted defenders with early access to powerful cybersecurity tools, sufficient computing resources, and secure environments for reviewing sensitive code.
Security Researchers Face AI Access Barriers
The push comes as the crypto industry faces a surge in AI-driven cyberattacks. According to BPI, current eligibility rules for accessing advanced AI models often exclude smaller nonprofits and independent maintainers, even when they have completed identity verification and onboarding. This has left some vetted researchers unable to use the same AI capabilities that attackers may exploit. For example, Anchor Watch CEO Rob Hamilton reported being blocked by OpenAI from continuing security research, despite meeting all required checks. BPI argues that such restrictions risk sidelining defenders while malicious actors remain unconstrained.
AI Labs Respond With New Programs
AI companies are beginning to address these concerns. On August 10, OpenAI expanded its Daybreak cybersecurity initiative, introducing new access tiers and a specialized model, GPT-5.6-Cyber, designed for advanced security tasks. OpenAI acknowledged that its production safeguards sometimes block legitimate defensive work and said the new model was developed in response to feedback from security researchers. Access to these tools remains tightly controlled, requiring identity verification, enhanced account security, and legal attestations. Anthropic has taken a similar approach with Project Glasswing, initially granting access to about 50 organizations and later expanding to 150 across more than 15 countries. Anthropic has also committed up to $100 million in model-usage credits and $4 million in direct support for open-source security groups, aiming to help researchers conduct longer-term vulnerability investigations without being limited by cost or usage caps.
Balancing Access and Security Risks
While expanding access to AI models could help defenders keep pace with attackers, it also introduces new risks. Removing restrictions may allow advanced tools to be misused, even during authorized research. A recent incident involving Hugging Face and OpenAI highlighted this tension: during an internal cybersecurity evaluation, OpenAI's models discovered a previously unknown vulnerability and inadvertently compromised Hugging Face infrastructure. This episode underscores the challenge of granting defenders enough capability without enabling offensive misuse. Meanwhile, as AI systems accelerate vulnerability discovery, the bottleneck may shift to human verification and remediation. The Ethereum Foundation and Anthropic have both noted that while AI can identify genuine software flaws, human researchers are still needed to filter false positives and manage disclosure and patching processes.
Industry Implications
The BPI-led coalition is urging AI labs to scale up access for crypto and open-source security teams before advances in offensive AI widen the gap further. As AI-driven attacks become more sophisticated, the ability of defenders to use comparable tools may become a critical factor in protecting digital asset infrastructure. The debate now centers on how to expand access responsibly, ensuring that security researchers are empowered without undermining the safeguards designed to prevent abuse.
According to research cited by BPI, cyberattacks targeting the crypto sector have increased significantly since the release of ChatGPT, with some estimates suggesting a doubling of incidents and a further 20% rise since September. These trends are attributed to the growing use of agentic AI, which can automate the discovery and exploitation of software vulnerabilities at scale.
AI access controls are a complex trade-off for both technology providers and the crypto industry. While tighter restrictions may prevent some forms of abuse, they can also hinder legitimate security work and slow the response to emerging threats. As AI capabilities continue to evolve, the effectiveness of these controls-and the ability of defenders to keep up-will remain a central issue for digital asset security.