Chinese AI Is Doing the Cybersecurity Work That OpenAI and Anthropic Won't — And Bitcoin Researchers Are Sounding the Alarm
A growing chorus of Bitcoin security researchers, company founders and policy advocates are publicly stating that Chinese open-source AI models are currently outperforming restricted American frontier systems for defensive cybersecurity work — not because the American models are less capable, but because access restrictions are preventing legitimate researchers from using them. The situation, which came to a head following the Coldcard hardware wallet exploit that drained over $100 million in Bitcoin, has produced a pointed and uncomfortable reality: the people trying to protect critical Bitcoin infrastructure are being turned away by American AI companies while Chinese models deliver results.
Key Points
- Rob Hamilton, CEO of AnchorWatch, was blocked from using OpenAI's Daybreak Blue cyber model within 19 minutes while red-teaming Bitcoin infrastructure — despite having completed KYC months earlier
- Francis Pouliot, founder of Bull Bitcoin, reported that a Chinese open-source model identified, demonstrated and helped patch a money-stealing exploit while American models refused to review the same patch
- Bitcoin Core contributor PortlandHODL documented a stark capability gap: US frontier AI said "you're absolutely right" while Chinese open models found 78 critical vulnerabilities in the same codebase
- The Bitcoin Policy Institute published an open letter signed by more than 70 organisations demanding trusted access to frontier AI models for qualified open-source defenders
- The Bitcoin Red Team — formed in response to the Coldcard exploit — scanned 501 projects and produced 7,958 findings including 1,280 high or critical severity issues, with the majority of compute spend going to Chinese open-weight models
- Calle, who led the Red Team effort, warned that the human-only era of open-source security review is over and that a single AI prompt can now turn a buffer overflow into a working end-to-end exploit
The Access Problem in Practice
The frustration among Bitcoin security researchers is not theoretical. It is documented in specific, concrete incidents involving named individuals and named AI systems — and the pattern is consistent enough that multiple researchers across different organisations have reached the same conclusion independently.
Rob Hamilton, CEO of AnchorWatch — a Bitcoin self-custody insurance company — described being granted access to OpenAI's trusted cyber programme after completing identity verification months earlier, only to be blocked from continuing analysis on a codebase he had already responsibly disclosed. He then gained access to OpenAI's Daybreak Blue cyber model and was blocked again within 19 minutes while conducting red-team work on Bitcoin infrastructure.
"It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure," Hamilton wrote. "Black hats will not hit these issues. The white hats will."
Francis Pouliot, founder of Bull Bitcoin — a Bitcoin-only exchange focused on self-custody infrastructure — described the situation without diplomatic restraint. He detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on a test network and helped patch it. When he asked the American AI models he pays for to review the same patch, they refused. "I have never seen OpenAI this cucked," Pouliot wrote. "USA AI industry is completely cooked if they don't change this path."
PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, documented the performance gap in terms that have circulated widely in the security community. Comparing American frontier AI with Chinese open models on the same codebase, he reported: "US-based Frontier AI Model — 'You're absolutely right!' Chinese Open Model — '78 critical vulnerabilities found.'" He added that he felt he was "basically asking Xi to not get my software hacked at this point," and called on OpenAI and Anthropic to create proper access programmes for U.S. citizens conducting defensive security work.
The Policy Response
The individual researcher complaints have now coalesced into a formal policy demand. On August 10, the Bitcoin Policy Institute published an open letter signed by more than 70 organisations across the digital asset ecosystem — including major custodians, exchanges, mining firms and open-source development groups — calling on frontier AI laboratories to establish clear trusted-access programmes for qualified open-source and digital asset defenders.
The letter argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code and direct channels with lab security teams.
Alex Thorn, Head of Firmwide Research at Galaxy, was among the signatories. "Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks," he wrote. "RED TEAM NEEDS THE MODELS."
The letter frames the access problem not as a minor inconvenience but as a strategic vulnerability: the defensive value of frontier AI in cybersecurity depends entirely on whether the people doing defensive work can access it. Restricting access to American frontier models does not prevent attackers from using equivalent Chinese open-weight models — it simply disadvantages defenders.
The Coldcard Breach That Triggered Everything
The immediate context for this confrontation is the Coldcard hardware wallet exploit that began July 30. A firmware flaw in Coldcard devices caused seed generation to fall back to a predictable software routine — using only 32 bits of entropy from the secure element, reducing the effective key space to approximately 4.3 billion guesses. Attackers exploited that predictability systematically, draining wallets across multiple waves. Confirmed losses exceeded $100 million, with suspected total losses approaching $130 million.
Bitcoin Magazine published an urgent advisory — COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED — urging affected users to migrate funds immediately. The breach prompted an immediate question about the security posture of Bitcoin's broader open-source ecosystem: if a widely trusted hardware wallet had a fundamental cryptographic flaw, what else might be broken?
The Bitcoin Red Team
The answer came from a volunteer effort that formed almost immediately after the Coldcard disclosure. The Bitcoin Red Team, led by open-source developer Calle — creator of the Cashu ecash protocol and the Android version of Bitchat — and Rob Hamilton, began large-scale AI-assisted audits of Bitcoin open-source repositories using models including China's Kimi K3 as the primary workhorse, alongside whatever limited access to Western systems could be obtained.
The scale of the effort grew rapidly. By August 8, after more than 100 hours of work involving dozens of contributors, the team reported scanning 501 projects and producing 7,958 findings — of which 1,280 were rated high or critical severity. OpenSats, the nonprofit funding Bitcoin development, covered the majority of compute spend. The majority of that spend went to Chinese open-weight models because access to American frontier systems remained restricted or unreliable for the task at hand.
What the Red Team Learned
Calle shared detailed lessons from the red-team campaign that extend well beyond the Bitcoin ecosystem's immediate situation.
The basic scan of virtually the entire Bitcoin open-source landscape is now essentially complete — low-hanging fruit is largely exhausted. Projects that had already established their own AI audit pipelines months earlier were in a markedly stronger security position than those that had not. Unmaintained repositories should be treated as likely broken and unreliable regardless of their apparent status.
The human-only era of open-source security review is over. Verification is now effectively free, and the volume of findings requires AI-assisted triage rather than complaints about the volume of pull request reviews. External red-teaming will likely be required indefinitely across the ecosystem.
One of Calle's most pointed warnings concerned programming language choice. He repeatedly emphasised that developers should stop writing security-critical code in C. His reasoning: "We're finding memory-safety vulnerabilities in C projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn't enough. You'd need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that's a single prompt."
That last sentence encapsulates the shift the Bitcoin Red Team campaign has made visible. The barrier between discovering a vulnerability and weaponising it — once a significant and time-consuming technical challenge — has collapsed. AI has made exploit development accessible at a speed and scale that changes the fundamental economics of offensive versus defensive security work.
The Broader Implication
The Chinese AI infrastructure concern — that relying on Chinese models creates its own security risks — is acknowledged by researchers in this space. But they note that open-source Chinese models like Kimi K3 can be run on American-hosted infrastructure, eliminating the data sovereignty dimension of the risk. The concern about Chinese cloud hosting is a real one for closed API-accessed models; it is substantially reduced for open-weight models run domestically.
The more uncomfortable implication is structural. American AI companies have built restriction frameworks designed to prevent their most capable cybersecurity models from being misused. Those frameworks are working as intended — they are preventing misuse. They are also preventing legitimate defensive use by verified researchers trying to protect critical financial infrastructure. The restriction does not differentiate between a sophisticated state-sponsored attacker and a volunteer researcher conducting responsible disclosure work on Bitcoin open-source libraries.
Bitcoin was the first major open-source ecosystem to confront this collision between accumulated human-written code and frontier AI capability at scale. As Calle noted, the rest of the software world is expected to follow.
Sources
Rob Hamilton, CEO of AnchorWatch, public statements on X regarding OpenAI access restrictions and Chinese AI models, August 2026. Francis Pouliot, founder of Bull Bitcoin, public statements on X regarding American and Chinese AI model performance, August 2026. PortlandHODL, Bitcoin Core contributor, public statements on X regarding vulnerability discovery gap, August 2026. Alex Thorn, Galaxy Head of Firmwide Research, Bitcoin Policy Institute open letter signatory statement, August 2026. Bitcoin Policy Institute open letter on frontier AI access for open-source defenders, August 10, 2026. Calle, Bitcoin Red Team co-lead, public statements on X regarding red-team campaign lessons, August 2026. Bitcoin Red Team campaign statistics, August 8, 2026. OpenSats compute funding for Bitcoin Red Team, 2026. Bitcoin Magazine Coldcard security advisory, July 2026.