Normal view

There are new articles available, click to refresh the page.
Before yesterdayBitcoin Magazine

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

By: Juan Galt
13 August 2026 at 12:18

Bitcoin Magazine

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

Bitcoin company leaders and open-source developers are publicly stating that Chinese AI models are currently outperforming restricted American frontier systems in defensive cybersecurity work, forcing researchers to rely on them to secure critical Bitcoin infrastructure.

Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance company, reported cripling American AI restrictions. After integrating OpenAI’s trusted cyber program (having already completed KYC months earlier), he was blocked from further analysis on a codebase he had already responsibly disclosed. “It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure,” Hamilton wrote. “Black hats will not hit these issues. The white hats will.” Days later, he gained access to OpenAI’s “Daybreak Blue” cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.

Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation bluntly. “I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin,” he posted. “USA AI industry is completely cooked if they don’t change this path,” he concluded, adding “Open-source Chinese LLMs. [orange heart emoji],” meaning that open Chinese models like Kimi K3 are actually helpful to Bitcoin. In a follow-up, Pouliot detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked the American models he pays for to review the same patch, they refused.

PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, publicly highlighted the performance gap. “US-based Frontier AI Model – ‘You’re absolutely right!’ Chinese Open Model – ‘78 critical vulnerabilities found.’ The implications of this are unfathomable,” he posted. In a follow-up, he added that he felt he was “basically asking Xi to not get my software hacked at this point,” calling for OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.

Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter demanding trusted access to frontier models for open-source defenders. “Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks,” he wrote. “RED TEAM NEEDS THE MODELS.”

On August 10, the Bitcoin Policy Institute — a Bitcoin and, of late, AI-focused policy think tank — published an open letter signed by more than 70 organizations across the digital-asset ecosystem, including major custodians, exchanges, mining firms, and open-source development groups. The letter calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code, and direct channels with lab security teams, stating that frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.

These statements reflect a broad pattern among Bitcoin security researchers: American models from OpenAI and Anthropic frequently refuse or restrict legitimate defensive work, even to users who are supposed to have been granted explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results. Concerns about hosting infrastructure of Chinese models being an attack vector can also be mitigated, since they are open source and can be run on American-hosted data centers, a trend that is likely to threaten the U.S. AI market if it continues.

Coldcard Exploit Triggers Ecosystem-Wide Response

The cybersecurity pressure became acute in the Bitcoin industry after a firmware flaw in Coldcard hardware wallets was exploited beginning July 30, resulting in the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine published an urgent advisory urging affected users to migrate funds: COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED.

In response, a volunteer effort known as the Bitcoin Red Team formed, led by open-source developer Calle (creator of Cashu and the Android version of Bitchat) and Rob Hamilton. The group has conducted large-scale AI-assisted audits of Bitcoin open-source repositories, using models including Kimi K3 as the primary workhorse alongside limited access to Western systems. Early results, covered by Bitcoin Magazine, showed thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.

By August 8, after more than 100 hours of work involving dozens of contributors, the team reported scanning 501 projects and producing 7,958 findings, of which 1,280 were rated high or critical severity. The majority of compute spend continued to go to Chinese open-weight models.

Lessons from the Red Team Campaign

Most recently, Calle shared lessons from the intensive red-team period. The effort has essentially completed a basic scan of virtually the entire Bitcoin open-source landscape; low-hanging fruit is largely exhausted, the developer wrote on this X account. Maintainers across projects have validated many of the critical and high-severity reports, while response times from projects vary widely and serve as a signal of overall health.

Key takeaways include the need for every project to maintain its own permanent AI audit pipeline going forward. Projects that began such reviews months earlier are in a markedly stronger position. Unmaintained repositories should be treated as likely broken and unreliable. 

Calle also warned that the human-only era of open-source security review is over; verification is now effectively free, and information overload must be handled with AI rather than complaints about PR slop. Multiple concurrent and diverse human approaches remain the strongest method for finding vulnerabilities, and external red-teaming will likely be required indefinitely. 

Calle also repeatedly emphasized that developers should stop writing security-critical code in C. In a follow-up post he explained: “we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.”

Bitcoin was the first major open-source ecosystem to confront this collision between accumulated human code and frontier AI capability. The rest of the software world is expected to follow.

This post Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns first appeared on Bitcoin Magazine and is written by Juan Galt.

Why Bitcoin Mining and AI Are Merging, Not Colliding

By: Nick Ward
12 August 2026 at 08:28

Bitcoin Magazine

Why Bitcoin Mining and AI Are Merging, Not Colliding

If you’ve scanned headlines over the last year, you’ve likely seen the prevailing market narrative: Bitcoin miners are pivoting to AI data centers, signaling a retreat from proof-of-work.

To casual observers, this looks like a surrender, proof that Bitcoin was just a temporary placeholder until a “better” compute workload arrived.

However, through the lens of power infrastructure and energy economics, that narrative gets the reality completely backwards. The migration isn’t a sign of Bitcoin’s weakness; it is a long-overdue, structurally bullish rebalancing of capital efficiency and global energy pricing.

Here is the underlying reality the market misunderstands.

AI vs. Bitcoin: Opposite Workloads, Same Megawatts

The misconception stems from assuming all digital workloads are created equal. In reality, Artificial Intelligence and Bitcoin Mining require completely opposite operational environments:

  • AI Training Clusters Are Fragile: If a 100-megawatt AI facility drops power mid-run, millions of dollars of LLM training state are destroyed. AI demands high-grade baseload power, ultra-low latency fiber, and 99.999% continuous uptime.
  • Bitcoin Miners Are Ultra-Flexible: Bitcoin mining is completely indifferent to latency or location. ASICs can operate anywhere power is cheap. Crucially, if grid power prices spike or local utilities demand load reduction, a miner can curtail power in seconds without losing data or damaging hardware.

The Power Bottleneck: Why Energized Sites Are the Ultimate Asset

AI hyperscalers face a massive speed-to-market bottleneck: securing new 100+ megawatt grid interconnections with utilities can take 3 to 5 years. Meanwhile, Bitcoin miners spent the last decade securing high-voltage interconnections, power purchase agreements (PPAs), and physical site footprint.

Rather than AI “pricing miners off the grid,” miners are acting as pragmatic energy arbitrageurs. They don’t care about the compute payload, they care about maximizing dollar yield per megawatt.

When post-halving mining margins tighten, leasing or retrofitting prime grid-tied sites for high-margin AI workloads becomes a natural capital allocation play. Miners aren’t being evicted; they are monetizing their most valuable asset: time-to-power.

Taming Balance Sheet Volatility

The primary structural weakness of public Bitcoin mining companies has always been balance sheet exposure during bear markets. When hash prices drop, debt-heavy miners are forced to dump mined Bitcoin reserves onto the open market to pay electricity bills and corporate overhead—creating downward price pressure.

The AI shift fundamentally alters this balance sheet dynamic:

  1. Predictable USD Cash Flow: Multi-year hosting leases signed with AI hyperscalers generate steady, high-margin dollar revenue.
  2. Reduced Forced Selling: With corporate overhead covered by AI revenue, operators no longer need to dump their Bitcoin treasury at market bottoms.
  3. The “Mullet” Data Center: Forward-thinking operators run a hybrid model, using high-margin AI workloads on grid-tied power to cover fixed costs, while using flexible Bitcoin mining to monetize off-peak power and provide lucrative demand-response services back to the grid.

The Bottom Line: Pure Energy Capitalism

The shift taking place across global data centers isn’t a trade-off where one technology “wins” and the other loses. It is a market optimization.

AI hyperscalers get the energized, grid-connected real estate they need to meet immediate compute demands without waiting half a decade in a utility queue. Bitcoin miners get predictable cash flows, lower cost of capital, and stronger balance sheets to navigate halving cycles.

Instead of competing for power, AI and Bitcoin infrastructure are converging into a symbiotic relationship, allocating every megawatt of global energy to its highest and best financial use.

Disclaimer: This content was prepared on behalf of Bitcoin For Corporations for informational purposes only. It reflects the author’s own analysis and opinion and should not be relied upon as investment advice. Nothing in this article constitutes an offer, invitation, or solicitation to purchase, sell, or subscribe for any security or financial product.

This post Why Bitcoin Mining and AI Are Merging, Not Colliding first appeared on Bitcoin Magazine and is written by Nick Ward.

The End of the Closed-Source Era Is at Hand: Obscurity Was Never Security

6 August 2026 at 14:43

Bitcoin Magazine

The End of the Closed-Source Era Is at Hand: Obscurity Was Never Security

Over the last few days, people who were trying to do everything right lost their Bitcoin. They bought a respected hardware signer, generated a seed offline using that device, and trusted the device to do the one thing a signer exists to do: produce a number no one else can guess. The Coldcard did not. A preprocessor guard that checked the wrong thing had quietly routed seed generation to a weak software PRNG (pseudorandom number generator), MicroPython’s Yasmarang, instead of the hardware entropy source. On some models the effective entropy collapsed to around 40 bits. The flaw shipped in March 2021 and sat in publicly readable firmware for more than five years. Attackers swept 500 addresses before anyone understood why; within days Galaxy Research’s tally reached 4,585 addresses and nearly $90 million; the attack is ongoing as of the date of this article.

Coinkite’s working assumption, with wide agreement on X, is that someone used AI to comb the publicly available firmware to find the bug. Whether or not that’s how this attacker found it, the next one will. While an AI-assisted audit was run weeks before the theft, it found nothing (potentially due to the capabilities of the model, potentially due to the specific construction of the search). Since the attack started, researchers have shown several frontier models locating the same flaw in minutes from a single prompt. The code sat open to human review for five years and no human caught it.

Coinkite had moved its firmware from a free-software license to source-available terms, MIT with a Commons Clause, after Foundation Devices used the code in a competing product. You could read the source but not build a business on it. It changed nothing. The bug lived in code a machine could read regardless of what the license permitted; it entered the tree, in fact, in the very rewrite that stripped out the last of the GPL code. The license change didn’t increase protection; it merely changed the economics of finding the bug.

In the age of highly skilled AI, everything that is distributed is readable, or soon will be. Strip a binary of its symbols, run it through a decompiler, and out comes the pseudo-C that greets anyone who has opened Ghidra: nameless variables, flattened control flow, functions labeled FUN_00401a20. Unreadable to most people. That high barrier to human understanding was the entire security premium of “closed source.”

A compiled program has no choice but to tell the truth. Code that stays encrypted cannot run. At the moment of execution the processor must receive the actual instructions, so whatever the program does, it hands the machine a complete and exact account of how to do it. The information is all there in the machine code. Obfuscation does not, and cannot, remove it.

If reading a binary sounds too hard for a machine to master soon, weigh it against what machines are already doing to problems far harder. Reading a binary is analysis: every fact you need is in front of you, and the work is extraction. Mathematical invention is another order of difficulty, because it demands an object no one has ever seen. At 02:19 UTC on July 20th, Levent Alpöge, a mathematician working with Anthropic’s Claude Fable 5, posted a counterexample to Keller’s Jacobian conjecture, a problem open since 1939 and hard enough to sit on Stephen Smale’s list of challenges for the twenty-first century. Generations had tried it. The disproof is three polynomials in three variables. Lean verified it within hours, and it is short enough for anyone to confirm in a computer-algebra system in about a minute.

The Jacobian fell in an afternoon, while the questioner was apparently watching the final match of the FIFA World Cup. In May an OpenAI model toppled the Erdős unit-distance conjecture, a question open since 1946; in late July a 30-year-old graph-theory conjecture fell to four prompts; between them came the Jacobian disproof and a run of other results that had stood for decades.

Set that pace beside the modest task of reading machine code already sitting out there on the Internet. Today’s models handle source and decompiler output better than raw bytes, so a fully closed binary keeps a thin margin. That margin is a cost speedbump, and it is eroding at the speed you are watching everywhere else. Betting security on how long it lasts means betting against a clock that is only speeding up.

The same capability that finds your entropy bug reads your proprietary method. This is the quieter casualty, and it impacts companies that never thought of themselves as exposed to open-source anything. Trade secrecy in shipped software was always just obscurity in a suit. The law has said so for as long as trade-secret law has existed: reverse engineering a product you lawfully possess is fair play, and therefore a secret survives only while that reverse engineering stays expensive. When the cost of extraction falls to a subscription and a prompt, the secret embodied in the code you hand your customers stops being one. Your clever algorithm, your undocumented format, your edge in the binary: legible to anyone who cares to look, on a timeline increasingly measured in minutes.

None of this necessarily makes open source safe. Heartbleed hid in the most widely deployed TLS library on earth for two years, because visibility without funded attention finds nothing. The xz backdoor showed that the open contribution model is itself an attack surface, one a patient adversary can walk through with a friendly face and two years of good commits. While openness once was a shield, it is no longer. What it does buy is reviewers who are permitted to look, builds which can be independently reproduced and verified, an exit when a vendor dies or turns, and acknowledgment that this all will happen whether you like it or not.

Now we must assume every line shipped will be read by someone who wishes harm, because it will be. The defender holds one structural advantage the attacker never will: time. You can turn the same frontier models on your own code before release, in the space between commit and ship, while the attacker waits for a binary that does not yet exist. Make your builds reproducible, so it ties back to the source and the source can be checked. Design to fail closed, and keep the trusted core small enough that one bug cannot take everything. For the specific business of holding Bitcoin, learn the lesson Coldcard is teaching in real time: own the entropy you cannot afford to have guessed, keep the secure element minimal and behind a published interface, and spread your keys across independent implementations, so that no single device, and no single vendor’s mistake, is the whole of your exposure.

For Bitcoin the stakes are unforgiving in a way they are not elsewhere, since mere knowledge of the private keys grants possession. The entropy bug has left permanent scars. Patching the generator does nothing for the seeds it already produced; a weak keyspace stays sweepable forever, and disclosure hands the attacker the recipe. We have watched this before. The Milk Sad vulnerability in the libbitcoin explorer tool, bx, seeded private keys from a 32-bit value, and attackers were draining the wallets it produced before the flaw was ever made public. Attackers keep their own schedule, invited or not. For money that cannot be clawed back, “findable eventually” is a synonym for “gone eventually.”

Bitcoin never trusted obscurity. The protocol is open, its rules checkable by anyone, its security resting not on secrets but on mathematics and incentives that hold in full view. The hardware and software we build around it deserve the same standard, because the alternative is no longer on the table. The choice was never open or closed. It was disciplined or exposed.

The broader lesson of this Coldcard situation is that having closed source software is like having a seed generated by a broken Coldcard; it looks good but it’s fundamentally built on sand. Everyone can read the code — the only question left is whether you acknowledge that fact, or you and your users learn it the way Coldcard’s users did, one drained address at a time.

This is a guest post by Colin Crossman, who is the Wyoming Deputy Secretary of State. Opinions expressed are entirely their own and do not necessarily reflect those of BTC Inc or Bitcoin Magazine.

This post The End of the Closed-Source Era Is at Hand: Obscurity Was Never Security first appeared on Bitcoin Magazine and is written by Colin Crossman.

NYSE-Listed AI Company Taps Lightning Network to Pay Employees In Bitcoin

30 July 2026 at 11:28

Bitcoin Magazine

NYSE-Listed AI Company Taps Lightning Network to Pay Employees In Bitcoin

Publicly traded AI operating system Vida Global (NYSE American: VIDA) has said it has started paying employees in Bitcoin using the Lightning network — but in a way where the company does not have the leading crypto on its balance sheet. 

The Austin, Texas-based company said Thursday that after a worker in Argentina asked to be paid in Bitcoin, the firm tapped Bitcoin infrastructure company Voltage to make the transaction. 

But the company is not keeping Bitcoin on its books: it simply sends the cash amount via Voltage’s platform, the employees receive payment in Bitcoin, and Vida’s balance sheet remains in dollars. 

“Vida has a global team, including team members in Argentina who prefer to be paid in Bitcoin because of challenges with their local currency,” Vida CEO Lyle Pratt said. 

“Voltage facilitates the Bitcoin payments, and we settle the balance in U.S. dollars at the end of the month, just like a standard vendor invoice. It has made offering Bitcoin payments remarkably simple for both our team and our finance operations.”

Pratt added the setup meets employee needs without adding crypto complexity to accounting.

Voltage CEO Graham Krizek said it was solving a mismatch between “global by default” AI companies and payment rails that haven’t kept up.

“Their team members get paid in seconds in the money they actually want, and their finance team never touches crypto,” he said. “When a public company runs part of its team compensation on Bitcoin rails and the books stay boring, that’s the point.”

Lightning is another network that skirts transactions around the main chain, cutting costs and increasing speed — originally designed so people could use Bitcoin for daily purchases.

Bitcoin maxis like Twitter co-founder Jack Dorsey have since integrated the network into their businesses, payments platform, Cash App and his PoS terminals, Square.

This post NYSE-Listed AI Company Taps Lightning Network to Pay Employees In Bitcoin first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Dubai-Based Emirates Airline Adds Bitcoin and Crypto Payments 

28 July 2026 at 16:08

Bitcoin Magazine

Dubai-Based Emirates Airline Adds Bitcoin and Crypto Payments 

People can now pay with Bitcoin to buy flights from Dubai-based airline Emirates. 

Working with Crypto.com, Emirates said Tuesday the customers now have the option to book flights using the crypto exchange’s payment feature.

Crypto.com and Emirates last year announced they would work together. 

Emirates’ Deputy President and Chief Commercial Officer Adnan Kazim said the move “reflects the rapidly evolving preferences of a younger, digitally fluent generation who manage their money and plan their journeys primarily from their phones and they expect the airlines they fly with to keep pace.”

Emirates first teased plans back in 2022 to implement Bitcoin payments; the latest move allows Crypto.com customers to use any digital assets to make payments. 

Under the new setup, travelers with a Crypto.com account can select Crypto.com Pay at checkout when booking on emirates.com or through the Emirates App. 

The option is limited for now to eligible UAE residents making bookings priced and settled in Emirati Dirham.

The integration runs through Crypto.com’s Dubai-licensed entity, which the company says was the first virtual asset service provider to receive a Stored Value Facilities license from the Central Bank of the UAE. 

The launch also feeds into wider government targets. It supports Dubai’s Cashless Strategy, part of the D33 Economic Agenda, which is aiming to make 90% of transactions across the emirate’s government and private sectors digital by the end of 2026. 

It follows on from an earlier Emirates partnership with Dubai Finance to advance digital payments, and comes after Crypto.com struck its own deal with Dubai Finance to accept digital payments for government services.

This post Dubai-Based Emirates Airline Adds Bitcoin and Crypto Payments  first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Core Scientific Adds More Bitcoin To Balance Sheet in Q2 Despite Selling Strategy

28 July 2026 at 13:23

Bitcoin Magazine

Core Scientific Adds More Bitcoin To Balance Sheet in Q2 Despite Selling Strategy

Nasdaq-listed miner Core Scientific is rebuilding its Bitcoin treasury after seeing its balance sheet shrink at the start of this year. 

In a regulatory filing Tuesday, the miner said it had a total of 848 Bitcoins — worth over $54 million at today’s prices — after finishing the first quarter of this year with 547 Bitcoins. 

Core Scientific finished 2025 with 2,537 but started aggressively selling coins to fund its transition to the AI and high-powered computing industry. 

But the miner has started stacking Bitcoin again, using coins from mining, in order to have a strong balance sheet. It added 301 coins this quarter alone. 

Selling Bitcoins can reduce reliance on equity issuance or additional borrowing, especially in a higher-interest rate environment. It also gives a company more cash on hand.

Core Scientific shares (CORZ) were trading about 2% lower Tuesday afternoon in New York. 

The company, which operates data centers across Alabama, Georgia, Kentucky, North Carolina, North Dakota, Oklahoma, and Texas, added that its revenue in the second quarter of this year rose sharply to $164.2 million from $78.6 million in Q2 2025. 

Gross profit rose to $70 million from $5 million in the same period as the year before. 

Core Scientific is one of a number of top publicly listed miners that have started directing resources to providing the infrastructure for high-powered computing.

On Tuesday, the miner signed a deal with chipmaker AMD for 2.5 gigawatts ‌of data center capacity. The deal will give ​AMD access to more than 500 megawatts of Core Scientific’s AI-ready ‌data ⁠center capacity. 

A number of Bitcoin miners have already gone all-in on the industry as minting the biggest digital coin by market cap becomes harder and demand for AI compute surges. 

Instead of dropping mining operations completely, a number of Bitcoin miners have instead marketed themselves as “compute” or “digital infrastructure” companies while switching between minting digital coins and providing compute for AI — depending on which is more profitable.

Branching out into AI data centers isn’t always easy for miners as the world of HPC requires more expertise with heating, ventilation and air conditioning systems than those for Bitcoin mining.

This post Core Scientific Adds More Bitcoin To Balance Sheet in Q2 Despite Selling Strategy first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

❌
❌