OpenAI blocks researcher Rob Hamilton from Bitcoin security analysis, pushing team toward Chinese AI models

3 hours ago 38

Rob Hamilton was in the middle of something genuinely useful. The AnchorWatch CEO had assembled a volunteer “Bitcoin Red Team” to run AI-powered security audits on open-source Bitcoin repositories, and the results were piling up fast. Then OpenAI pulled the plug.

On August 9, 2026, Hamilton publicly disclosed that OpenAI’s “trust cyber program” had blocked him from continuing his analysis on a codebase that had already been responsibly disclosed. This happened despite Hamilton having completed the platform’s onboarding and KYC processes. The fix was straightforward, if ironic: he switched to Chinese open-source models.

What the Red Team actually found

The Bitcoin Red Team wasn’t a vanity project. It was a direct response to a serious incident: a late-July 2026 vulnerability disclosure involving Coldcard hardware wallets that exposed a flaw leading to the theft of more than 1,000 BTC.

Hamilton, alongside developer Calle and roughly 16 other volunteers, decided to take a systematic approach. Using cutting-edge AI models, the team set out to scan as many open-source Bitcoin-related repositories as they could, as quickly as possible.

The pace was remarkable. In the first 30 hours alone, the Red Team scanned over 390 repositories and recorded 4,962 findings. Of those, 85 were categorized as critical and more than 635 as high-severity. The reproduction rate sat at roughly 21%, meaning about one in five flagged issues could be independently verified as real vulnerabilities.

Total AI compute spending for the project landed somewhere between $20,000 and $40,000. The team used a mix of models including Kimi K3 from Moonshot AI (which did most of the heavy lifting), GPT Sol with OpenAI’s Cyber Harness, Anthropic’s Claude Fable and Opus, and GLM 5.2.

The findings were privately disclosed to repository maintainers, following standard responsible disclosure practices.

The access problem

OpenAI wasn’t the only platform to push back. Anthropic also imposed access restrictions in the early stages of the project. Both companies had already put Hamilton through their verification processes. He’d done the paperwork. He’d been approved. And then his access was revoked anyway.

Hamilton described the OpenAI blockage as a policy “local minima,” a term borrowed from optimization theory that essentially means the system found a comfortable resting point that isn’t actually the best outcome. He tagged US officials in his public disclosure to highlight the regulatory challenges that compliant researchers face when trying to use American AI tools for legitimate security work.

The practical result was a migration to Kimi K3, a model developed by Chinese AI company Moonshot AI. The team found it less restrictive for their purposes. That’s a sentence worth sitting with for a moment: US-based security researchers, working to protect Bitcoin infrastructure, were pushed toward Chinese AI models because American platforms wouldn’t let them do the work.

After the project gained visibility and public attention, OpenAI reportedly allowed some access again.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article