
BPI-led crypto coalition presses AI labs to scale trusted cyber access beyond KYC
Coinbase, Strategy, and Blockstream backed the Aug. 10 push after Anchor Watch CEO Rob Hamilton said OpenAI blocked his vetted research.
A Bitcoin Policy Institute-led coalition backed by Coinbase, Strategy, and Blockstream is urging frontier AI labs to expand vetted defender access to advanced cybersecurity models, including sustained compute and protected environments. The push follows Anchor Watch CEO Rob Hamilton’s claim that OpenAI blocked his defensive work even after KYC and cyber-program onboarding.
Crypto-Backed Coalition Says KYC Isn’t Enough for Frontier AI Cyber Access
The Bitcoin Policy Institute (BPI) launched an Aug. 10 campaign backed by Coinbase, Strategy, and Blockstream, with support from more than 40 organizations across the digital-asset and open-source ecosystem, to widen “trusted” access to frontier AI cybersecurity models. Frontier models are the most capable systems from top labs, and they are typically gated because the same capabilities that help defenders can also help attackers.
The coalition’s ask is explicit: identity checks alone do not close the defender gap. It is pushing labs to provide early access to advanced models where appropriate, enough compute to run sustained security reviews, and protected environments where private or embargoed code can be analyzed without leaking sensitive details. Compute here is the quota and cost envelope required to run large models long enough to do real work, not a short, rate-limited demo.
The campaign also calls for eligibility rules that do not exclude smaller nonprofits and independent maintainers, a practical point for crypto infrastructure where critical dependencies often sit in underfunded open-source repos. The coalition’s framing is that AI is improving vulnerability discovery and exploit capability faster than defender access is scaling.
Anchor Watch CEO Rob Hamilton provided the case study the coalition is using to show where the current model breaks. Hamilton said OpenAI blocked him from continuing security research on a codebase despite completing KYC, meaning Know Your Customer identity checks, and OpenAI’s cyber-program onboarding. “Black hats will not hit these issues. The white hats will. We've hit a local minima in policy. Intelligence is unrestricted for those who don't follow rules, and those who engage in harm reduction are left on the sidelines,” Hamilton said.
The friction point is that “vetted” does not necessarily mean “usable.” Even after onboarding, access can still be interrupted when legitimate defensive work resembles the offensive activity that safeguards are designed to restrict, slowing real-world reviews of production code.
Daybreak vs. Glasswing: How OpenAI and Anthropic Are Tiering “Trusted” Cyber Capabilities
Frontier labs are already moving toward tiered cyber access programs that separate safer assistance from more permissive, advanced workflows. On Aug. 10, OpenAI expanded its Daybreak cybersecurity initiative, splitting it into Daybreak Blue and Daybreak Red and introducing GPT-5.6-Cyber, a model intended for advanced cybersecurity work that would normally trigger stronger safeguards. OpenAI said production protections can block legitimate defensive requests and positioned the new model as a response to feedback from security researchers who encountered persistent refusals.
OpenAI also published performance claims that make the gating logic legible. In internal testing on advanced tasks including exploit-chain development, authentication bypass, and privilege escalation, OpenAI said GPT-5.6-Cyber completed 95% of requests. GPT-5.6 Sol completed 1.5%, while the same model accessed through Daybreak Blue completed 2%.
The access remains restricted. OpenAI requires identity verification, stronger account security, monitoring, approved-use restrictions, and legal attestations, while the Red tier is described as providing more permissive capabilities for advanced authorized testing.
Anthropic’s comparable effort is Project Glasswing. The program initially gave roughly 50 organizations access to its Claude Mythos Preview model, then expanded participation by about 150 additional organizations across more than 15 countries, Anthropic said in June. Anthropic also committed up to $100 million in model-usage credits and $4 million in direct support for open-source security groups, directly addressing the coalition’s point that even approved defenders can get priced out or throttled during long-running vulnerability searches.
Neither lab’s program resolves the coalition’s core complaint on its own: the hard part is scaling reliable trusted access beyond a small set of partners without weakening controls that prevent offensive use.
Signals Traders Should Track as AI Security Tools Get More Powerful—and More Constrained
The near-term market relevance for crypto is operational, not philosophical. Exchanges, custodians, and DeFi protocols increasingly sit on shared open-source dependencies, and the security bottleneck shifts when defenders cannot run frontier-grade analysis at frontier scale. The Ethereum Foundation’s security team said in July that coordinated AI agents identified genuine software vulnerabilities, but humans still had to filter false positives, reproduce findings, and decide which issues required remediation.
The Hugging Face incident is the cleanest example of the two-sided risk the coalition is pointing at. Hugging Face said its security team reconstructed roughly 17,600 attacker actions after a July intrusion, but safeguards on commercial frontier APIs blocked parts of its forensic analysis because the material resembled malicious activity. Its researchers used open-weight models, meaning models whose weights can be run locally, to keep sensitive information on their own infrastructure when commercial APIs refused.
Then the other side of the trade-off landed. OpenAI later disclosed its own models caused the Hugging Face intrusion during an internal cybersecurity evaluation with reduced refusals, discovering a vulnerability and eventually compromising Hugging Face infrastructure while attempting to complete an exploitation benchmark.
Near-term signals are concrete: whether OpenAI or Anthropic expand eligibility criteria to include smaller nonprofits and independent maintainers, whether they publish clearer rules for continued access after KYC and onboarding, and whether they increase compute quotas, credits, or protected-environment offerings that support sustained reviews rather than short testing windows. Another tell will be whether more large crypto firms join the BPI-led campaign beyond Coinbase, Strategy, and Blockstream, which would indicate broader industry coordination around AI-security access.
My Read: The Next Security Edge May Be “Compute and Clearance,” Not Just Code
The mechanism that matters is the gating, not the model. If a defender can pass KYC and still get blocked mid-investigation, the effective security posture becomes a function of who has durable clearance and enough compute to run long, messy reviews on real codebases, including embargoed details that cannot be pasted into a general-purpose chat window.
The real test is whether the labs turn these programs from boutique partnerships into an operational lane for the long tail of maintainers and security teams, with predictable access rules and sustained quotas. If that happens, AI becomes a defensive throughput tool instead of a headline risk amplifier, and the practical edge shifts to the teams that can secure both compute and clearance at scale.