Forty Firms, One Open Letter, No Named Recipient
On 10 August 2026 the Bitcoin Policy Institute published an open letter, co-signed by more than 40 companies and organizations across the digital-asset industry, including Coinbase, Block, BitGo, Blockstream, Galaxy, MARA, Strategy, Strike, Trezor, Chaincode Labs, Bitwise, Anchorage Digital, ARK Invest, and Bitcoin developer funds such as Brink and Btrust. The letter does not name a single company. It is addressed, as reported by crypto trade press, to "the world's leading AI labs" as a class - meaning OpenAI, Anthropic, Google DeepMind and Meta are the implicit but unnamed audience.
The ask is narrow on paper: early, controlled access to the most cyber-capable frontier models before their public release, enough compute budget to run meaningful security reviews, a secure channel for examining embargoed or private code, eligibility that extends to independent maintainers and small nonprofit teams rather than only large companies, and a direct line to each lab's security team for reporting what researchers find. The letter explicitly does not ask for unrestricted public access to models with advanced cyber capability - it asks for a controlled program, run by the labs, that qualified defenders could apply to join.
The Evidence the Coalition Brought
The letter leans on two pieces of evidence. First, a volunteer effort the organizers call the Bitcoin Red Team has used AI tools to find thousands of vulnerabilities across hundreds of open-source projects in the space, working only with weaker, publicly available models rather than the frontier systems the letter is requesting. Second, BTCPay Server, an open-source payment processor, disclosed a critical flaw that attackers had already exploited to drain funds from Lightning Network nodes before the same AI-assisted research effort found and reported it.
The letter frames the stakes in a single figure: crypto platforms lost more than $634 million to hacks in April 2026 alone, the worst monthly total since the Bybit theft, according to DefiLlama data the coalition cited. Bitcoin itself, the letter notes, secures more than $1 trillion in value, all of it resting on open-source code that a comparatively small number of maintainers can review.
The Program They Want Already Exists, and Nobody Can See Its Rules
What the coalition is asking labs to build already has a name in Washington, though the letter does not use it. Executive Order 14409, signed 2 June 2026, required the White House to finish a voluntary early-access framework by 1 August, under which the federal government may hold a covered frontier model for up to 30 days before it is shared with other "trusted partners" - a category selected jointly by the model's developer and the government. The White House confirmed on 1 August that the framework was complete on schedule. It has not published the criteria a partner has to meet, the process for applying, or a right to know why an application failed.
That is the structure the Bitcoin coalition is petitioning to join, whether or not its members know it by that name. A letter addressed to no one in particular, asking to be let into a program whose admission rules are classified, is not a negotiation - it is a request for discretion, made to counterparties who face no obligation to explain a rejection or even acknowledge that an application was received. As of publication, none of the major labs implicitly named by the coalition had issued a public response.
Europe Has No Program to Petition At All
For a US buyer or defender, the discretionary path described above is at least a path, however opaque. For a European one, it does not exist. The EU AI Act's Article 51 sets a published, calculable line for which models count as posing systemic risk - 10^25 floating point operations of training compute, or an equivalent Commission designation - but it creates no counterpart to the trusted-partner mechanism, no defender-access lane, and no channel through which a European open-source maintainer securing the same Bitcoin protocol could apply for early access to a frontier model's cyber capabilities.
A Bitcoin Core contributor working from Berlin or Amsterdam has, at present, exactly the same standing as one working anywhere else with no US federal relationship at all: none. Any EU owner running critical infrastructure that depends on open-source cryptographic or financial code should treat this gap, not the US framework's opacity, as the more immediate problem to raise with vendors and national cybersecurity agencies this quarter.
Read next: The US Frontier AI Threshold Is Now Classified | Congress Demands Answers on AI Safety-Test Breaches



