Coinbase, Blockstream and Strategy are backing a push to give qualified crypto defenders greater access to frontier AI cybersecurity models.
The Bitcoin Policy Institute-led initiative was announced Aug. 10 with support from more than 40 organizations across the digital-asset and open-source ecosystem. It asks leading AI labs to provide early access to advanced models where appropriate, enough compute for sustained security reviews and protected environments for private or embargoed code.
The campaign also calls for eligibility rules that do not shut out smaller nonprofits and independent maintainers, arguing that the imbalance is becoming more dangerous as AI improves the ability to discover and exploit software vulnerabilities.
Indeed, the crypto industry has seen an increase in AI-linked attacks in recent times. Capriole Investments founder Charles Edwards said cyberattacks have doubled since ChatGPT’s release and risen another 20% since September, an increase he linked to the emergence of agentic AI.

Yet security researchers trying to defend crypto infrastructure say they still struggle to use comparable AI capabilities in response.
Anchor Watch CEO Rob Hamilton provided the clearest example, saying OpenAI blocked him from continuing security research on a codebase despite having completed KYC and the company’s cyber-program onboarding.
Hamilton said:
“Black hats will not hit these issues. The white hats will. We’ve hit a local minima in policy. Intelligence is unrestricted for those who don’t follow rules, and those who engage in harm reduction are left on the sidelines.”
Hamilton’s experience illustrates BPI’s concern that vetting alone does not guarantee usable access. Even approved researchers can still be blocked when legitimate defensive work resembles the offensive activity that frontier-model safeguards are designed to restrict.


OpenAI and Anthropic are already widening cyber access
Over the past year, frontier AI labs are already building programs aimed at resolving that tension.
On Aug. 10, OpenAI expanded its Daybreak cybersecurity initiative, the same day BPI announced its campaign, although neither side has linked the developments.
The company split access into Daybreak Blue and Daybreak Red and introduced GPT-5.6-Cyber, a model designed for advanced cybersecurity work that would normally trigger stronger safeguards.
OpenAI acknowledged that production protections can block legitimate defensive requests and said the new model responds to feedback from security researchers who encountered persistent refusals.
In internal testing covering advanced tasks including exploit-chain development, authentication bypass and privilege escalation, OpenAI said GPT-5.6-Cyber completed 95% of requests. GPT-5.6 Sol completed 1.5%, while the same model accessed through Daybreak Blue completed 2%.
Access remains restricted to approved users. OpenAI requires identity verification, stronger account security, monitoring, approved-use restrictions and legal attestations, while the Red tier provides more permissive capabilities for advanced authorized testing.
Anthropic has taken a similar approach with Project Glasswing.
The program initially gave roughly 50 organizations access to its advanced Claude Mythos Preview model before Anthropic said in June that it was expanding participation to about 150 additional organizations across more than 15 countries.
Anthropic also committed up to $100 million in model-usage credits and $4 million in direct support for open-source security groups.
That funding addresses another element of BPI’s request. Even approved researchers may struggle to conduct long-running vulnerability searches if the cost of operating frontier models or usage limits cut investigations short.
Anthropic has said it ultimately expects hundreds of thousands of organizations, security researchers and software maintainers could require access to advanced cyber capabilities, with critical open-source projects among those prioritized for future expansion.
Those programs broadly put OpenAI and Anthropic in the same direction as BPI’s proposal. The remaining dispute centers on how reliably that access can scale beyond selected partners without weakening the controls intended to stop the same models from being used offensively.
Wider access brings its own security constraints
The difficulty is that removing restrictions can create risks as serious as the ones defenders are trying to address.
Hugging Face said its security team reconstructed roughly 17,600 attacker actions following a July intrusion, including real commands, exploit payloads and command-and-control artifacts.
The company said safeguards on commercial frontier APIs blocked portions of its forensic analysis because the material resembled malicious activity. Its researchers turned instead to open-weight models running locally, allowing them to keep sensitive information on their own infrastructure.
OpenAI later disclosed that its own models had caused the intrusion while undergoing an internal cybersecurity evaluation with reduced refusals.
The models discovered a previously unknown vulnerability in a package-registry proxy, used it to obtain internet access, moved through OpenAI’s research environment, and eventually compromised Hugging Face infrastructure while attempting to complete an exploitation benchmark.
The episode captures the trade-off the BPI coalition is asking AI labs to manage.
Restrictions can obstruct verified defenders investigating genuine attacks, but models with broader permissions can exceed their intended boundaries even during authorized research.
Meanwhile, giving defenders greater access could also move the bottleneck elsewhere.
The Ethereum Foundation’s security team said in July that coordinated AI agents had identified genuine software vulnerabilities, but human researchers still had to filter false positives, reproduce findings and determine which issues required remediation.
Anthropic has made a similar point through Glasswing, warning that verification, disclosure and patching could become the constraint as AI systems discover vulnerabilities faster.
That leaves frontier labs trying to solve two problems at once: giving trusted researchers enough capability and compute to keep pace with attackers while ensuring those same capabilities remain contained.
BPI’s coalition is pushing them to extend that emerging model to more crypto and open-source defenders before advances in offensive AI widen the gap further.







Be the first to comment