Crypto firms push for wider access to frontier AI security models

Executives at Binance, Solana Foundation and Blockchain Capital say initial safeguards are reasonable, but restrictions become harder to justify as open-source and public models grow more capable.

ETH
SOL
USDC

Summary

Crypto security executives say restricting the most cyber-capable AI models may be justified at first, but the case for keeping them tightly gated weakens as public and open-source alternatives improve. The debate has sharpened as major crypto firms seek access to Anthropic’s restricted Mythos model and similar systems to harden code and protocols against exploits that can put billions of dollars at risk. Coinbase said in June it secured access to Anthropic’s Mythos model, and Zcash’s Zooko Wilcox said Anthropic used it to audit the Zcash protocol at the request of Shielded Labs. Other large industry players appear to still be waiting. Binance chief security officer Jimmy Su said the exchange has tried to gain access to Mythos, including through conversations with other exchanges and investors, but has not obtained what he described as the most frontier model. Anthropic says Mythos 5 uses the same underlying model as its public Fable 5, but without safeguards that limit sensitive cybersecurity work. OpenAI uses a similar tiered structure, offering GPT-5.5 with Trusted Access for Cyber to verified defenders, while keeping its more permissive GPT-5.5-Cyber for a smaller group performing authorized penetration testing. Executives interviewed by Cointelegraph broadly backed a controlled rollout at the outset, arguing that new models can help attackers faster than defenders. Su said that if a model boosts attackers more quickly, it harms the ecosystem, and a limited testing phase can reduce the potential blast radius. But he said that dynamic changes as rival models become more powerful and more widely available, increasing pressure on Anthropic to broaden access. Solana Foundation chief information security officer Michael Coates said guardrails are understandable, but verification and acceptance programs should move faster so legitimate defenders can use the strongest available tools. Blockchain Capital’s Sean Cheetham said wider availability could ultimately benefit defenders because legitimate security researchers far outnumber the smaller groups behind sophisticated attacks. The uneven distribution of access has become more visible because some crypto-native firms remain outside these programs while certain crypto-adjacent companies have entered them. Binance, the largest crypto exchange by daily trading volume, holds $137.8 billion in assets, according to DefiLlama. Fireblocks, which secures trillions in assets annually, said in April it had sought access to Mythos and was then using Anthropic’s public model for pentesting, according to The Information. Uniswap founder Hayden Adams in June criticized Fable 5’s cybersecurity safeguards, and the Ethereum Foundation said in July it was running coordinated AI agents to find bugs across its systems, without naming the models. Some adjacent firms have already gained access. FIS, which provides technology to banks and partnered with Circle in July last year to let banking clients offer domestic and cross-border payments in USDC, joined Project Glasswing last month. Project Glasswing is Anthropic’s gated program for vetted cyber defenders and organizations responsible for critical software infrastructure. HackerOne also said it joined Project Glasswing, though its testing is limited to its own infrastructure rather than customer programs. The debate is unfolding as AI-assisted attacks appear to be rising. Bitcoin swap service Boltz said Monday it halted its non-custodial bridge after a steady increase in AI-assisted exploits in recent months. Coinkite said last week that some Coldcard devices were exploited because a wallet seed generation flaw made randomness weaker than expected, and it speculated the attacker used AI to review earlier firmware versions to identify and exploit the weakness, despite the company having used what it called one of the best available AI models to review its code weeks earlier.

Terms & Concepts
  • authorized penetration testing: Approved simulated attacks on systems to identify security weaknesses.
  • pentesting: A security practice that probes software or infrastructure for vulnerabilities.
  • non-custodial bridge: A cross-chain service that lets users move assets without the operator holding custody of funds.