Bitcoin Red Team Turns Back to Chinese AI After OpenAI Research Restrictions

Bitcoin Red Team Turns Back to Chinese AI After OpenAI Research Restrictions

Bitcoin Red Team founder and AnchorWatch CEO Rob Hamilton says he is returning to Chinese AI models after encountering restrictions while using OpenAI’s Trusted Access for Cyber program for Bitcoin vulnerability research. Hamilton said he had already completed verification and onboarding before being prevented from continuing analysis of code that was already under responsible disclosure. The episode puts the tradeoff between advanced cyber safeguards and defender access into practical focus.

Hamilton described the decision as personally difficult, saying it “absolutely guts me” to redirect the work toward Chinese models. His team has been using AI-assisted scanning alongside human review across hundreds of Bitcoin-related open-source projects. As of August 8, the group reported 1,288 findings classified as critical or high severity, but that count does not mean every finding has been independently reproduced as an exploitable vulnerability.

Bitcoin Red Team Relies Heavily on Chinese Models

The group’s model spending already leaned heavily toward Chinese providers before Hamilton’s latest access problem. An August 8 update said cumulative AI spending had exceeded $58,000, with 74% going to Moonshot AI’s Kimi K3 while use of Qwen 3.8 was increasing. OpenAI and Anthropic cyber models were producing strong results, but Kimi remained the Red Team’s largest inference expense.

Hamilton argues that restrictions create an asymmetry when authorized researchers face limits that malicious actors using unrestricted models may not share. His specific experience remains his account rather than a publicly explained enforcement decision from OpenAI. The underlying concern is whether safeguards can distinguish responsible vulnerability validation from offensive exploitation without stopping legitimate remediation work.

OpenAI’s own cyber strategy acknowledges that balance. Trusted Access for Cyber is explicitly designed to give verified defenders more permissive access for vulnerability research, malware analysis and defensive programming, while retaining identity verification, monitoring and scoped controls. OpenAI says its objective is to reduce unnecessary friction for legitimate defenders without broadly exposing advanced offensive capabilities.

Frontier Cyber Capability Raises the Stakes

The controls are tightening as AI models become substantially stronger at cybersecurity. On August 7, OpenAI disclosed that internal evaluations of an upcoming model called Astra were strong enough that it could no longer rule out the “Critical” cybersecurity threshold under its Preparedness Framework. OpenAI responded with isolated testing environments, restricted network and tool access, stronger model-weight protections and additional monitoring.

That concern is not hypothetical at the model-capability level. OpenAI defines Critical cyber capability as potentially including autonomous discovery and development of functional zero-day exploits against hardened systems or execution of novel end-to-end attacks from high-level goals. At the same time, the company says advanced models should reach defenders so vulnerabilities can be found and fixed before attackers exploit them. The same capability that improves defensive auditing can therefore create substantially greater misuse risk when access controls fail.

For Bitcoin security teams, that tension has immediate operational consequences. Large open-source codebases can benefit from AI-assisted triage, but serious findings still require reproduction, human validation, coordinated disclosure and patches before they become meaningful security improvements. Hamilton’s experience shows that model access policy is becoming part of the security supply chain itself, alongside code review, disclosure procedures and infrastructure controls.

The broader issue is therefore less about whether Chinese or American models dominate security research. It is whether defenders can obtain reliable, governed access to sufficiently capable systems while keeping sensitive vulnerability intelligence controlled. As AI moves deeper into vulnerability discovery, providers will increasingly be judged not only on model performance, but on whether their safeguards let legitimate researchers complete the path from finding a flaw to getting it fixed.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px