比特币行业警告:中国AI超越受限美国模型
Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns
Bitcoin Magazine
比特币杂志
Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns
中国人工智能击败受限的OpenAI和Anthropic网络安全模型,比特币行业发出警告
Bitcoin company leaders and open-source developers are publicly stating that Chinese AI models are currently outperforming restricted American frontier systems in defensive cybersecurity work, forcing researchers to rely on them to secure critical Bitcoin infrastructure.
比特币公司领导者和开源开发者公开表示,中国的人工智能模型目前在防御性网络安全工作中表现优于受限的美国前沿系统,迫使研究人员依赖它们来保护关键的比特币基础设施。
Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance company, reported cripling American AI restrictions. After integrating OpenAI’s trusted cyber program (having already completed KYC months earlier), he was blocked from further analysis on a codebase he had already responsibly disclosed. “It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure,” Hamilton wrote. “Black hats will not hit these issues. The white hats will.” Days later, he gained access to OpenAI’s “Daybreak Blue” cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.
Rob Hamilton,比特币自我托管保险公司AnchorWatch的首席执行官,报告了美国人工智能限制的严重问题。在整合了OpenAI的可信网络计划(数月前已完成KYC)后,他被阻止对已经负责任地披露的代码库进行进一步分析。“作为一个爱国的美国人,我不得不这样做,这让我心碎,但我将重新使用中国的开源模型来进行研究,以保护比特币基础设施,”Hamilton写道。“黑帽不会触及这些问题。白帽会。”几天后,他获得了OpenAI的“Daybreak Blue”网络模型的访问权限,但在对比特币基础设施进行红队测试时,19分钟内再次被阻止。
Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation bluntly. “I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin,” he posted. “USA AI industry is completely cooked if they don’t change this path,” he concluded, adding “Open-source Chinese LLMs. [orange heart emoji],” meaning that open Chinese models like Kimi K3 are actually helpful to Bitcoin. In a follow-up, Pouliot detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked the American models he pays for to review the same patch, they refused.
Francis Pouliot,专注于自我托管基础设施的比特币专用交易所Bull Bitcoin的创始人,直率地描述了这一情况。“我从未见过OpenAI如此受制。现在它受制得令人难以置信。不仅是为了安全,而是为了任何与比特币相关的事情,”他发帖说。“如果美国人工智能产业不改变这条道路,就完全完蛋了,”他总结道,并补充说“开源中国大语言模型。[橙心表情]”,意味着像Kimi K3这样的中国开放模型实际上对比特币有帮助。在后续帖子中,Pouliot详细描述了一个中国开源模型如何在他审计的一个项目中识别出一个盗取资金的漏洞,在回归测试中演示了该漏洞,并帮助修补了它。当他要求他付费的美国模型审查同一个补丁时,它们拒绝了。
PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, publicly highlighted the performance gap. “US-based Frontier AI Model – ‘You’re absolutely right!’ Chinese Open Model – ‘78 critical vulnerabilities found.’ The implications of this are unfathomable,” he posted. In a follow-up, he added that he felt he was “basically asking Xi to not get my software hacked at this point,” calling for OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.
PortlandHODL,一位为AnchorWatch构建的比特币核心贡献者,公开强调了性能差距。“美国前沿人工智能模型——‘你说得完全正确!’中国开放模型——‘发现78个关键漏洞。’这意味着什么,深不可测,”他发帖说。在后续帖子中,他补充说,他觉得“基本上是在请求习近平不要让我的软件被黑客攻击”,并呼吁OpenAI和Anthropic为从事防御性安全工作的美国公民创建适当的访问程序。
Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter demanding trusted access to frontier models for open-source defenders. “Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks,” he wrote. “RED TEAM NEEDS THE MODELS.”
Galaxy公司全公司研究主管Alex Thorn签署了比特币政策研究所的一封公开信,要求为开源防御者提供对前沿模型的受信任访问权限。他写道:“美国人不应该依赖中国的人工智能来保护自己、他们的项目、公司或客户免受网络攻击。红队需要这些模型。”
On August 10, the Bitcoin Policy Institute — a Bitcoin and, of late, AI-focused policy think tank — published an open letter signed by more than 70 organizations across the digital-asset ecosystem, including major custodians, exchanges, mining firms, and open-source development groups. The letter calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code, and direct channels with lab security teams, stating that frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.
8月10日,比特币政策研究所——一个专注于比特币及近期人工智能的政策智库——发布了一封公开信,由数字资产生态系统中的70多个组织签署,包括主要托管机构、交易所、矿企和开源开发团体。这封信呼吁前沿人工智能实验室为合格的开源和数字资产防御者建立明确的受信任访问计划。信中指出,当前的限制和安全防护措施使合法的安全研究人员无法访问最强大的模型,迫使他们依赖能力较弱的开放权重替代品,而复杂的攻击者却不受此类限制。签署方要求提前访问具有网络能力的模型、足够的计算资源、用于审查代码的安全环境,以及与实验室安全团队的直接沟通渠道,并指出如果防御者获得公平访问权,前沿人工智能可能成为最强大的防御技术之一。
These statements reflect a broad pattern among Bitcoin security researchers: American models from OpenAI and Anthropic frequently refuse or restrict legitimate defensive work, even to users who are supposed to have been granted explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results. Concerns about hosting infrastructure of Chinese models being an attack vector can also be mitigated, since they are open source and can be run on American-hosted data centers, a trend that is likely to threaten the U.S. AI market if it continues.
这些声明反映了比特币安全研究人员中的一种普遍模式:来自OpenAI和Anthropic的美国模型经常拒绝或限制合法的防御工作,即使对据称已被授予明确访问权限的用户也是如此,而像Kimi K3这样的中国模型则没有同样的防护措施,并且正在提供已确认的结果。对中国模型托管基础设施可能成为攻击载体的担忧也可以得到缓解,因为它们是开源的,可以在美国托管的数据中心运行,如果这种趋势持续下去,很可能威胁到美国的人工智能市场。
Coldcard Exploit Triggers Ecosystem-Wide Response
Coldcard漏洞引发生态系统广泛响应
The cybersecurity pressure became acute in the Bitcoin industry after a firmware flaw in Coldcard hardware wallets was exploited beginning July 30, resulting in the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine published an urgent advisory urging affected users to migrate funds: COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED.
在Coldcard硬件钱包的固件漏洞于7月30日开始被利用后,比特币行业的网络安全压力变得严峻,导致超过1亿美元的比特币因种子熵不足而被盗。Bitcoin Magazine发布了一份紧急公告,敦促受影响的用户转移资金:COLDCARD安全风险:需要立即采取行动。
In response, a volunteer effort known as the Bitcoin Red Team formed, led by open-source developer Calle (creator of Cashu and the Android version of Bitchat) and Rob Hamilton. The group has conducted large-scale AI-assisted audits of Bitcoin open-source repositories, using models including Kimi K3 as the primary workhorse alongside limited access to Western systems. Early results, covered by Bitcoin Magazine, showed thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.
作为回应,一个名为“比特币红队”的志愿者组织成立,由开源开发者Calle(Cashu和Android版Bitchat的创建者)和Rob Hamilton领导。该组织使用包括Kimi K3作为主要工作模型,并有限访问西方系统,对比特币开源仓库进行了大规模AI辅助审计。早期结果由《比特币杂志》报道,显示在数百个项目中发现了数千个问题,包括数十个严重问题,支出主要由OpenSats承担。
By August 8, after more than 100 hours of work involving dozens of contributors, the team reported scanning 501 projects and producing 7,958 findings, of which 1,280 were rated high or critical severity. The majority of compute spend continued to go to Chinese open-weight models.
截至8月8日,经过超过100小时的工作,涉及数十名贡献者,该团队报告扫描了501个项目,产生了7,958个发现,其中1,280个被评为高严重性或严重性。大部分计算支出继续用于中国的开放权重模型。
Lessons from the Red Team Campaign
红队行动的经验教训
Most recently, Calle shared lessons from the intensive red-team period. The effort has essentially completed a basic scan of virtually the entire Bitcoin open-source landscape; low-hanging fruit is largely exhausted, the developer wrote on this X account. Maintainers across projects have validated many of the critical and high-severity reports, while response times from projects vary widely and serve as a signal of overall health.
最近,Calle分享了密集红队时期的经验。这项工作基本上完成了对整个比特币开源领域的初步扫描;低垂的果实基本已被摘尽,开发者在X账户上写道。各项目的维护者已经验证了许多严重和高严重性的报告,而各项目的响应时间差异很大,这可以作为整体健康状况的信号。
Key takeaways include the need for every project to maintain its own permanent AI audit pipeline going forward. Projects that began such reviews months earlier are in a markedly stronger position. Unmaintained repositories should be treated as likely broken and unreliable.
关键要点包括每个项目未来都需要维护自己永久的AI审计管道。几个月前开始此类审查的项目处于明显更有利的位置。未维护的仓库应被视为可能损坏且不可靠。
Calle also warned that the human-only era of open-source security review is over; verification is now effectively free, and information overload must be handled with AI rather than complaints about PR slop. Multiple concurrent and diverse human approaches remain the strongest method for finding vulnerabilities, and external red-teaming will likely be required indefinitely.
Calle还警告说,仅靠人工的开源安全审查时代已经结束;验证现在实际上免费,信息过载必须用AI处理,而不是抱怨PR垃圾。多种并发且多样的人工方法仍然是发现漏洞的最强方法,并且外部红队可能无限期需要。
Calle also repeatedly emphasized that developers should stop writing security-critical code in C. In a follow-up post he explained: “we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.”
Calle还反复强调,开发人员应该停止用C编写安全关键代码。在后续帖子中,他解释说:“我们在C项目中发现了内存安全漏洞,这些漏洞在许多其他语言中默认被阻止。过去,发现一个简单的缓冲区溢出还不够。你需要一个高技能的黑客将漏洞转化为可用的端到端漏洞利用。今天,这只需一个提示。”
Bitcoin was the first major open-source ecosystem to confront this collision between accumulated human code and frontier AI capability. The rest of the software world is expected to follow.
比特币是首个面对积累的人类代码与前沿AI能力碰撞的主要开源生态系统。预计软件世界的其他部分也将紧随其后。
This post Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns first appeared on Bitcoin Magazine and is written by Juan Galt.
这篇文章《中国AI击败受限的OpenAI和Anthropic网络安全模型,比特币行业发出警告》首次出现在《比特币杂志》上,作者是Juan Galt。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力