
Author: Nancy, PANews
When you store cryptocurrency tokens in what you thought was a secure hardware wallet, one day a hacker finds the "lock-picking key" in just a few minutes, aided by a tireless AI.
That's right, AI large models are entering the battlefield of crypto security offense and defense.
As AI large models continue to iterate, on one hand, they are lowering the technical threshold for complex crypto attacks, significantly increasing the speed of exploiting vulnerabilities and attacks; on the other hand, they are also becoming important tools for discovering vulnerabilities, locating risks, and accelerating fixes in the crypto industry. This trend is particularly evident in the Bitcoin ecosystem, which has a market value exceeding one trillion dollars.
In the competition between Chinese and American AI large models, relying on model capabilities and open-source ecosystem advantages, domestically developed large models are gradually becoming the "firefighters" for the crypto community to conduct security audits.
Hackers Accelerate with AI
Not long ago, the hardware wallet Coldcard suffered a massive hacker attack, shocking the domestic and international crypto community. It was reported that this attack resulted in the theft of over 100 million dollars' worth of Bitcoin assets. In addition to the significant financial losses, this incident further undermined the market's long-standing confidence in Bitcoin's self-custody security.
Coldcard has long been regarded as a high-security "safe" in the crypto market. Due to its open-source code, there are suspicions within the community that attackers may have utilized AI to conduct code reviews of older firmware, discovering a similar five-year-old vulnerability from a vast amount of historical code. More notably, after the incident, the community used the AI model Claude Code, which accurately located the vulnerability in just about 8 minutes.
This month, the non-custodial Bitcoin exchange service Boltz announced an indefinite suspension of its Bitcoin exchange service. One of the reasons disclosed is that the iterative speed of AI-assisted attacks has exceeded the team's ability to repair vulnerabilities. Over the past few months, Boltz has continuously faced automated AI detection attacks and dealt with multiple exploitation incidents. However, the pace of recent attacks has significantly accelerated, with suspected multiple resource-rich attacking organizations simultaneously launching attacks against its platform. Unable to ensure safe operations during the repair period, Boltz ultimately suspended its Swap service, which was subsequently taken over by an anonymous Bitcoin team.
As large models continue to iterate, hackers are weaponizing AI, significantly compressing the cost and speed of crypto attacks. In the past, hackers required substantial time to discover complex vulnerabilities through code reviews and attack path design. Now, AI is automating more and more parts of this process. Attackers can analyze code, locate vulnerabilities, and even further complete more covert exploitation and attack processes at a lower cost and faster speed.
For example, the North Korean hacker group Kimsuky has recently further expanded the use of generative AI. In addition to creating phishing bait with AI, the organization has built a standalone local large language model (LLM) environment and a retrieval-augmented generation (RAG) system, attempting to further automate intelligence extraction and attack processes. In terms of specific attack tactics, Kimsuky has begun using generative AI to create highly realistic virtual assets and financial documents aimed at implementing more targeted spear-phishing attacks, targeting sensitive data including cryptocurrency wallet information, Gmail accounts, and website registration records.
85 Severe Vulnerabilities Scanned in 30 Hours, Building "Self-Defense Firewall" Becomes Essential
The attack side is upgrading, and the defense side must speed up to keep up.
This month, a volunteer security organization called Bitcoin Red Team, led by Cashu founder and Bitcoin open-source developer Calle and AnchorWatch CEO Rob Hamilton, conducted a large-scale AI-assisted security audit of the Bitcoin open-source ecosystem, covering wallets, cryptographic libraries, and infrastructure projects.
In less than 30 hours, the team scanned 390 Bitcoin-related open-source projects and submitted 4,962 security findings, including 85 severe vulnerabilities and 635 high-risk vulnerabilities, averaging about 2.31 severe or high-risk issues discovered per person per hour, with a daily scanning cost of around 10,000 dollars.
Calle pointed out that the large amount of historical technical debt accumulated over time in open-source code is colliding fiercely with efficient AI code analysis tools. The vast majority of unmaintained projects likely contain vulnerabilities and should be considered unsafe by default until proven safe. Particularly, the Lightning Network software responsible for achieving faster and lower-cost Bitcoin payments, due to its high technical complexity, has code conditions that are "worse than average," making audits significantly more challenging than other categories.
He emphasized that in the AI era, the past complaints of "low-quality PR" or "low-quality audits" are over.
Project parties must establish their own AI audit pipelines to quickly filter and reproduce reports using AI. Future external red team testing (a method of security assessment that simulates real attackers) may require long-term continuity. Projects that began building their own AI security and audit processes months in advance are now in a clearly advantageous position.
Chinese Open-Source Models "Fill the Gap", Industry Calls for Open Access to AI Labs
In the global large model competition, Chinese and overseas manufacturers are not only competing over performance and cost but are also heading down two different development paths. Leading models in China generally choose the open-source route, while top overseas manufacturers mostly adhere to a closed-source strategy.
This divergence in routes is becoming an important resource affecting the security capabilities of the crypto ecosystem. Currently, compared with overseas closed-source models, Chinese open-source models are unexpectedly becoming important tools for the Bitcoin community to conduct code reviews, vulnerability mining, and security research.
In the investigation of the Coldcard attack, Galaxy research director Alex Thorn revealed that some American large language models impose restrictions on security research, impacting researchers' ability to trace stolen funds. Due to difficulties in smoothly utilizing relevant models, the team even had to turn to Chinese open-source AI models to help protect user assets and conduct on-chain tracking.

Similar circumstances have also arisen in the security audits conducted by the Bitcoin Red Team. The team disclosed that they are currently using the Chinese AI model Kimi K3 from Dark Side of the Moon and Zhipu AI's GLM 5.2 for scanning vulnerabilities in Bitcoin open-source projects. Calle pointed out that during the security research process, developers often face limitations imposed by model vendors like OpenAI and Anthropic regarding their security policies. Even when researchers complete KYC and apply for Trusted Access, they may frequently encounter refusals or usage restrictions. In contrast, the restrictions on Chinese open-source models are relatively few, making them more suitable for large-scale code analysis and security audits. This led Calle to question the current policies that restrict white-hat researchers while failing to effectively curb black-hat behavior.
Just a few days ago, the Bitcoin Policy Institute (BPI) along with Anchorage Digital, BitGo, Bitwise, Blockstream, Kraken, Ledger, MARA, Trezor, and dozens of other crypto institutions issued an open letter, urging cutting-edge AI labs to establish or expand long-term trusted access plans for Bitcoin and other open-source software developers, allowing security teams to use advanced AI capabilities in advance to discover and fix vulnerabilities.

The open letter argues that cutting-edge AI is rapidly changing the landscape of cybersecurity offense and defense. Advanced models are already able to analyze large codebases, identify potential vulnerabilities, and accelerate complex technical tasks, but these capabilities are also being exploited by attackers. Meanwhile, many open-source security teams currently lack channels to access cutting-edge models, and the security restrictions on public AI models may hinder legitimate security research, forcing some developers to rely on less capable open-weight models for critical code reviews.
The letter specifically points out that crypto open-source maintainers, including Bitcoin Core, currently cannot access certain AI labs' cybersecurity access programs. As the Bitcoin network currently protects over one trillion dollars in assets, any vulnerabilities in open-source infrastructure could jeopardize users' life savings. BPI also disclosed that it has received multiple reports from open-source maintainers stating that complex attackers, including potential foreign adversaries, are continuously launching attacks using advanced AI capabilities at a pace that small maintenance teams can hardly withstand.
BPI emphasizes that cutting-edge AI is expected to become one of the most powerful defensive technologies, but this is contingent on defenders of critical infrastructure being able to access it before attackers exploit these capabilities. To close the offensive and defensive capability gap, BPI calls on AI labs to provide early and controlled access to cutting-edge cybersecurity models for certified open-source defenders, including pre-release versions where appropriate; to provide sufficient computing power and long-term usage quotas for Agents; to establish secure environments for analyzing private or unpublished code; to extend access to small organizations, non-profits, and independent maintainers; and to create direct coordination channels with AI lab security teams for vulnerability disclosures and fixes.
Overall, AI is bringing crypto security into a new competition of speed and capability. In the future, those who can access and effectively utilize cutting-edge AI more quickly are more likely to gain an advantage in this offensive and defensive game.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。