A Bitcoin security researcher says he lost access to an OpenAI capability used in his ongoing vulnerability reviews, forcing him to shift back to open-source Chinese AI models. The move underscores a broader concern within parts of the crypto security community: that the most advanced AI systems may be difficult for โdefendersโ to use, even when the intent is to reduce risk.
In a post on X Tuesday, AnchorWatch CEO Rob Hamilton said he began integrating OpenAIโs Trust & Cyber capabilities into his Bitcoin Red Team effort on Saturday, only to find his access restricted the next morning. โIt absolutely guts me as a patriotic American to have to do this,โ Hamilton wrote, adding that he would return to using Chinese open-source models to continue protecting Bitcoin infrastructure.
Key takeaways
- Rob Hamilton says access to OpenAIโs Trust & Cyber was restricted shortly after he began integrating it into Bitcoin Red Team work.
- Hamilton frames the change as a defensive tradeoff: open AI models are accessible, while certain frontier tools may be harder for defenders to retain.
- Bitcoin Red Team conducts vulnerability scanning across hundreds of open-source Bitcoin-related repositories using a mix of AI assistance and human review.
- Recent hacks in the hardware wallet space have increased pressure on teams trying to detect issues earlier in the development lifecycle.
How Bitcoin Red Team is using AI to find vulnerabilities
Bitcoin Red Team is a volunteer effort that scans a large set of open-source Bitcoin-related repositories for potential vulnerabilities. According to Hamiltonโs account, the work relies on AI tools combined with human verification, with the goal of identifying weaknesses that may otherwise go unnoticed or be discovered only after exploitation.
The groupโs efforts have reportedly intensified following a widely discussed incident involving a Coldcard hardware wallet hack, which earlier reporting described as resulting in more than $100 million in stolen Bitcoin. While Hamiltonโs post does not quantify how the OpenAI access affected the rate or quality of findings, it does connect the research workflow to a broader urgencyโnamely, that attackers are actively searching for flaws in the systems people rely on to keep funds secure.
What Hamilton says changed after integrating OpenAI Trust & Cyber
Hamiltonโs explanation is straightforward: he started using OpenAIโs Trust & Cyber capabilities to support his teamโs review process, then lost the ability to continue the investigation that same week. He said he was โprevented from being able to continue the investigation in a further effort to make sure their code changes are sufficientโ and also to determine whether other issues remained undiscovered.
In a follow-up argument about the incentive structure for AI access, Hamilton suggested there is a โlocal minima in policy,โ implying that rules governing the availability of intelligence-focused AI capabilities may unintentionally narrow who can use them for defensive purposes. He added that while โblack hatsโ would not hit these issues, โwhite hatsโ could be left on the sidelines if the tooling is restricted.
Hamiltonโs characterization is notable because it positions the problem less as a technical limitation of AI and more as an access and policy constraint affecting security research workflows. For investors, users, and builders, the practical concern is that fewer defender teams may be able to run high-end analysis at scaleโat the exact moment when vulnerabilities across crypto infrastructure need faster detection.
Broader friction over โfrontierโ AI access in crypto security
This complaint fits into a pattern that has already been raised by crypto executives. Earlier coverage from Cointelegraph noted that many of cryptoโs largest players were โstill waiting to gain accessโ to powerful new AI models to strengthen their code from attacks, with only a limited number able to obtain it. In that context, Hamiltonโs experience appears as a micro-level example of how access can be unevenโeven for teams working on vulnerability discovery rather than exploitation.
The tension is that crypto ecosystems canโt rely solely on open-source tooling if the industryโs risk profile increasingly demands rapid review of complex codebases. Yet, if leading AI providers constrain usage in ways that make defensive experimentation difficult to sustain, security efforts may end up dependent on a patchwork of what is available rather than what is best suited for the task.
Why the shift back to open-source models matters
Hamilton said he would return to Chinese open-source models after the access restriction. That change is significant for two reasons.
- Continuity: If defender access to frontier systems is inconsistent, researchers may need fallback approaches they can run without interruptions. Open-source models can be deployed and iterated on without waiting for new permissions.
- Coverage and speed: Teams scanning โhundredsโ of repositories depend on automated support to review large volumes. If access to an advanced tool is removed midstream, the research cadence and scope can be affected unless an alternative system fills the gap quickly.
At the same time, Hamiltonโs stance does not necessarily imply that open-source models are always inferior. Instead, his argument is that defensive research is being forced to operate within the boundaries of whatever AI is availableโwhile attackers face fewer barriers to pursuing harmful goals. That framing raises a question for the community: how can security research leverage advanced AI while still operating under restrictions intended to prevent misuse?
For readers tracking crypto risk, this story is less about who โhasโ cutting-edge AI at any given moment and more about whether defender capability can be maintained over time. The next inflection point will be whether access policies are clarified, expanded, or made more predictable for security-focused use casesโespecially as vulnerabilities continue to be discovered across wallets and other critical infrastructure.
Hamiltonโs update leaves one key uncertainty: what specifically triggered the restriction and whether it was temporary or permanent. What readers should watch next is whether other security teams report similar access changes, and how quickly research workflows adapt without losing the ability to uncover vulnerabilities before they reach production.






