The Bitcoin industry is in a state of flux, with a growing divide between the tools available to defenders and those wielded by attackers. In a recent letter, over 30 prominent Bitcoin and cryptocurrency firms have called on major AI labs to provide open-source security researchers with early access to their most advanced models. This move is a direct response to the increasing sophistication of cyber threats and the need for more robust defenses.
The letter, organized by the Bitcoin Policy Institute, highlights a critical issue: Bitcoin Core developers, responsible for maintaining the network's software, face significant constraints when it comes to accessing powerful security tools. These developers are locked out of trusted-partner programs and limited by safety filters on public models, which hinder their ability to proactively identify and patch vulnerabilities.
In contrast, attackers have unrestricted access to these advanced models, giving them a significant advantage. The letter emphasizes that the current situation is akin to defenders using a weaker sword against an opponent's nunchaku. This imbalance is further exacerbated by the rapid spread of new offensive capabilities through public models, stolen corporate systems, and purpose-built hacking tools.
The signatories, including industry giants like Coinbase, Block, and ARK Invest, along with nonprofit developer funds, are making a compelling case for change. They are requesting five key measures: early access to the most advanced cyber-capable models, sufficient computing resources for thorough reviews, secure environments for private code examination, eligibility for small and independent maintainers, and direct communication channels with lab security teams.
This call for action comes at a critical juncture. Recent exploits against BTCPay Server and Lightning nodes, some of which were uncovered by an AI-powered volunteer group called the Bitcoin Red Team, have demonstrated the effectiveness of AI in identifying vulnerabilities. These exploits have already drained merchant Lightning nodes, highlighting the real-world consequences of the current security landscape.
The letter's timing is not coincidental. It follows the disclosure of a critical flaw in BTCPay Server, which was exploited by attackers. The Bitcoin Red Team's efforts have also been instrumental in uncovering thousands of critical bugs across various Bitcoin projects, including the one that led to BTCPay's patch. These developments underscore the urgency of the signatories' request.
In conclusion, the Bitcoin industry is at a crossroads, with the need for stronger defenses becoming increasingly apparent. The letter's call for early access to advanced AI models and improved collaboration between developers and AI labs is a necessary step towards a more secure future for the cryptocurrency ecosystem. As the industry continues to evolve, addressing these security concerns will be crucial to maintaining the integrity and trustworthiness of Bitcoin and its associated infrastructure.