Community Trust ScoreVerified
Rob Hamilton is furious. The CEO of AnchorWatch and driving force behind the Bitcoin Red Team went public with a finding that’s hard to ignore: 1,288 critical and high-level vulnerabilities identified across the Bitcoin ecosystem as of Saturday. And the tool he wanted to use to dig deeper? Off limits.
Hamilton had been running OpenAI’s Trust & Cyber capabilities through his Bitcoin Red Team work — a volunteer-driven group that combines AI analysis with manual code review to hunt for weaknesses across open-source Bitcoin repositories. But shortly after plugging those tools in, he hit a wall. Access got cut. No detailed explanation, no workaround. Just a door that closed. So he did something that clearly stings: he went back to Chinese open-source AI models. “It absolutely guts me as a patriotic American to have to do this,” Hamilton said, not hiding the frustration at all.
That quote landed hard in certain corners of the crypto security world.
1,288 Vulnerabilities and a Wallet Hack Worth $100M
The Bitcoin Red Team’s work didn’t happen in a vacuum. The group ramped up its efforts following a breach involving the Coldcard hardware wallet — a device widely trusted in Bitcoin circles — that led to more than $100 million in Bitcoin being compromised. That breach put real urgency behind what might otherwise look like academic threat modeling. It’s not theoretical. Money walked out the door.
With that backdrop, Hamilton’s team has been pushing hard. The 1,288 figure covers critical and high-level vulnerabilities, and the group is still going. But Hamilton says the restrictions on advanced AI access are making it genuinely harder to investigate whether existing code changes are actually sufficient, and whether there are undiscovered issues still sitting in the codebase. That’s a real problem when you’re trying to stay ahead of people who aren’t playing by the same rules.
The irony he keeps coming back to: malicious actors don’t face these restrictions. They can access powerful intelligence tools freely, without the ethical guardrails that slow down legitimate security researchers. The defenders are running with weights on. The attackers aren’t.
A Policy Gap That’s Leaving White Hats Behind
Hamilton’s situation is probably not unique. Last month, industry leaders noted that only a small number of people in the crypto space had managed to get access to the newer, more powerful AI models. Most didn’t. And that gap matters a lot when you’re trying to do serious code analysis on infrastructure that holds billions of dollars in value.
The Bitcoin Red Team is volunteer-driven — that’s worth sitting with for a second. These aren’t well-funded government agencies or corporate security teams with unlimited budgets. They’re people doing this work because they think it matters, using whatever tools they can get their hands on. When the best tools get restricted, the fallback options are… not nothing, but not ideal either.
Chinese open-source AI models can do real work. Hamilton isn’t saying they’re useless. But he’s clearly not happy about the tradeoff, and the patriotic framing he used wasn’t accidental. There’s a geopolitical dimension here that sits awkwardly alongside the practical security question.
It’s murky. The policy logic behind restricting access to advanced AI tools probably has something to do with preventing misuse — fair enough, in principle. But the execution seems to be hitting the wrong people. Hamilton’s team is focused on harm reduction. They’re trying to find vulnerabilities before bad actors do. Blocking them from the best available tools doesn’t make Bitcoin safer. It probably makes it less safe.
And the Coldcard hack makes that point with $100 million worth of emphasis.
The broader industry concern is real too. Crypto infrastructure is complex, the attack surface is large, and the pace of development means new code ships constantly. Keeping up with that requires serious tooling. Right now, some of the people most motivated to do that work can’t get what they need.
Hamilton’s team keeps going anyway. They’ve got 1,288 vulnerabilities logged, a recent major breach as a reference point, and a growing frustration with the policy environment they’re operating in. Whether that frustration translates into any actual change in access policy — unclear. No timeline on that. No commitments from anyone named in the source.
What’s clear is that the Bitcoin Red Team found 1,288 problems, lost access to the tools they wanted, and is now doing the work with Chinese open-source models instead.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
How many vulnerabilities did the Bitcoin Red Team find?
As of Saturday, the Bitcoin Red Team identified 1,288 critical and high-level vulnerabilities across the Bitcoin ecosystem.
Why did Rob Hamilton switch to Chinese AI models?
Hamilton switched after losing access to OpenAI’s Trust & Cyber tools shortly after integrating them into the Bitcoin Red Team’s research work.





