Bitcoin Brief

America Is Throttling the Defenders Who Protect Bitcoin

Criminals will use unrestricted AI tools whether compliant users are allowed to or not. Bitcoin's defenders should have access to the same capabilities.

9 min read
America Is Throttling the Defenders Who Protect Bitcoin
Share
TFTC - Truth for the Commoner

Bitcoin Brief

Sup, freaks.

Open-weight AI models have made corporate guardrails a one-sided handicap. Criminals will use whatever tools work. The people protecting open-source financial infrastructure are still expected to ask permission.

The policy outcome is ridiculous.

Let's get into it.


LEAD STORY

America Is Throttling the Defenders Who Protect Bitcoin

The people attacking open-source financial software do not care about an AI lab's acceptable-use policy. They do not complete Trusted Access onboarding. They do not submit a responsible disclosure plan. They do not wait for a safety team to decide whether their work is legitimate.

The defenders do.

That asymmetry is becoming dangerous. A Bitcoin Policy Institute post announcing a new open letter asks frontier AI labs to establish standing trusted-access programs for qualified defenders of open-source financial infrastructure. It calls for controlled early access, sufficient compute for long-running security reviews, secure environments for private or embargoed code, eligibility for independent and nonprofit maintainers, and direct channels for coordinated disclosure.

BPI has identified the right problem. I think the proposed solution is too timid.

Guardrails are not a sensible core defense in a world where capable open-weight models exist outside those guardrails. Restrictions bind the law-abiding. They do not bind criminals. Criminals do not, by their very nature, respect laws, acceptable-use policies or voluntary safety rules. They will use whatever tools are available if those tools help them commit a crime or sustain an attack.

Pretending otherwise does not create safety. It creates a capability gap between the people willing to follow the rules and the people trying to break the system.

Open-source software secures the internet, communications systems, national-security infrastructure, global markets, bitcoin wallets, signing devices, nodes, payment networks and cryptographic libraries. Bitcoin raises the stakes because it is a bearer asset. If an attacker finds a weakness in a bank, the path from access to money may still require fraud, extortion or a resale market. If an attacker extracts a private key, the money can move immediately and the transaction does not come with a chargeback desk.

BPI's concern is that frontier models can compress the time between vulnerability discovery and exploitation. The labs see those capabilities before they reach open weights, leaked accounts and specialized offensive tools. BPI says it has received multiple independent reports from open-source maintainers facing sophisticated actors, including potential foreign adversaries, using advanced AI capabilities to sustain attacks at a pace small teams struggle to absorb. BPI supplies that account, but it is not proof that every recent incident belongs to one coordinated campaign. The underlying resource problem is obvious either way.

We watched it play out during the Bitcoin Red Team campaign. Rob Hamilton reported that OpenAI's cyber controls blocked deeper defensive work even after he completed Trusted Access onboarding and KYC. His team moved the work to Chinese open-source models.

Read that again. An American defender identified himself, explained the work and accepted the compliance process. The American frontier lab still stopped him. The unrestricted model became the practical alternative.

Nobody is safer for it.

The cost of that capability gap arrived yesterday when LNp2pBot shut down. Its operators say they spent months improving security while absorbing attack losses, but could no longer match what they described as an army of script kiddies armed with AI models. They suspended the service indefinitely and promised to cover the few pending user payments themselves.

We do not know who attacked LNp2pBot or which tools they used. We do know a privacy-focused Lightning service with public code and a small team could no longer afford to defend itself. The government did not shut it down. Attack economics did.

America should stop pretending asymmetric restrictions are safety. They are a subsidy for attackers. Law-abiding citizens, companies and open-source projects trying to do good in the world should have untethered access to the same class of tools criminals can obtain and use without permission. Frontier-grade models can be deployed defensively with incredible effect. They can audit enormous codebases, hunt vulnerabilities, model attacks, accelerate patches and help small teams absorb pressure that would otherwise overwhelm them.

The answer is not a better permission slip. It is capability parity. Criminals already operate as if guardrails do not exist. Defenders should not be forced to fight with one hand tied behind their backs.

Give the good guys the tools.


SIGNAL

AI CREDIT

NVIDIA Is Building a Credit Market Backed by AI Compute

NVIDIA signed memorandums of understanding with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR for independent platforms designed to mobilize more than $500 billion of third-party capital over time. Jensen Huang says NVIDIA may, in selected deals, provide a limited residual-value support mechanism for up to 25% of an opportunity, assessed project by project and designed to complement, not replace, independent underwriting. Goldman reports that its AI investment-grade credit basket trades at 128 basis points, up 29.9 basis points YTD, while CDS activity across NVDA, AMD and AVGO rose sharply around seller-financing and guarantee announcements. The real development is not blanket GPU insurance. NVIDIA has not disclosed the 25% denominator, beneficiary, trigger or duration. It is trying to make compute acceptable institutional collateral while independent investors build a market for credit backed by it.


BITCOIN SECURITY

LNp2pBot Was Exhausted by Attackers

LNp2pBot suspended all activity indefinitely after what operator Francisco Calderón described as sustained attacks, losses absorbed by the team and months of security work that failed to overcome a resource mismatch. He said the project could not fight an "army of script kiddies armed with AI models." The team plans to resolve the few pending payments directly and says users will not bear the losses. Calderón's statement establishes the project's explanation, not the attackers' identity or exact tooling. The simpler economic lesson is enough. Public code gives attackers a white-box target, bearer assets provide liquid rewards, and a small privacy project can be forced to fund defense continuously. Open source makes repair and verification possible. It also lets every attacker study the target. Without better tools, shared security infrastructure and durable funding, more small teams will reach the same wall.


GLOBAL LIQUIDITY

Japan Bought Time, Not a Stronger Yen

The Bank of Japan's July meeting opinions kept a tightening bias and raised the possibility that hikes could arrive faster than the prior semiannual pace. J.P. Morgan keeps October as its base case, says September is possible and models a 2% policy rate by the end of 2027. Goldman estimates Japanese authorities bought up to $85 billion of yen over July 30 and 31, while a Safra note using CFTC data says yen shorts fell by 117,939 contracts, leaving 45,473 net shorts as of Aug. 4. Those bank figures are forecasts and estimates, not BoJ guidance. Intervention removed a crowded short and bought policymakers breathing room. It did not remove the global-liquidity risk created by rising Japanese rates, a weak currency and trades funded in yen. The carry trade has been squeezed. It has not been proven dead, and none of this dictates bitcoin's next move.


INSTITUTIONAL ACCOUNTABILITY

Fauci's Private Pregnancy Concern Belongs in the Public Record

Senator Ron Johnson's first phone release includes a Jan. 25, 2021 text attributed to Anthony Fauci saying fever and a cytokine response after a second dose "theoretically could be associated with miscarriage in the 1st trimester." That message documents an early theoretical concern, not an observed safety signal or proof that vaccination caused miscarriages. On its own, the released message does not establish what Fauci later said publicly, whether the concern persisted, or how officials weighed it against the observational data then available. It also belongs beside my new conversation with Jessica Rose, "Fauci's Paper Trail: How the Lab Leak Was Buried", which traces the broader documentary record around Fauci's emails, diary, Proximal Origin and pressure to accelerate the vaccine pipeline. The episode supplies institutional context. It did not cover this newly released pregnancy text.


FREEDOM TECH

Maple Is Turning the Private AI Agent Into a Real Workspace

Maple Agent v3.3.2 improves the agent harness, tool use and protocol support while making active work easier to follow. The sidebar now shows unread and running states, project and task details, status cards and direct access to project folders. The release notes also confirm current Goose and RMCP 3 support, more resilient initial-stream retries, model-choice persistence, semantic task titles and macOS GUI discovery for MCP commands. Mark Suman's demo runs Kimi K3, but he says capacity is not ready for broad access. GLM 5.2 remains the available default as the beta expands. The important advance is not another benchmark. It is the workflow becoming legible enough for an agent to live across real folders, projects and concurrent tasks without trapping the user in another chat box. Agent Connections remains feature-gated and off unless enabled.


Sponsored

CASH APP

Cash App lets users buy, earn, send and spend bitcoin.

For a limited time, new customers can get $21 added to their balance. Use code TFTC10 when you sign up, then send at least $5 to a friend within the first two weeks. Terms apply.

Get started with Cash App

Disclosure: Sponsored by Bitcoin at Block. Bitcoin services are provided by Block, Inc. Bitcoin is not FDIC insured and involves risk, including monetary loss. See the Bitcoin disclosures.

See the Bitcoin disclosures
Sponsored

SALT OF THE EARTH

Salt of the Earth makes electrolyte drink mixes containing sodium, potassium, magnesium, and calcium, with flavored and unflavored options.

Shop Salt of the Earth

⚡ FREEDOM TECH CORNER

BTCPay Is Paying the Defenders

The open-source security model works only if disclosure, reproduction and recovery are funded. BTCPay Server says it donated 0.21 BTC to Craig Raw and 0.21 BTC to the Bitcoin Red Team for responsibly disclosing its recent critical vulnerability.

Friends and supporters of the project also committed a recovery bounty equal to 10% of funds recovered, capped at 3 BTC for a full recovery. BTCPay says the bounty can be split among people who provide useful information and will be coordinated with victims. Actionable information can be sent to security@btcpayserver.org.

These are not grants for abstract research. They pay the people who found the weakness and create an incentive to help victims recover stolen funds. Open-source maintainers cannot rely on goodwill while attackers chase liquid rewards. If we want better disclosure and faster repairs, the reward structure has to point in that direction too.


DATA SNAPSHOT

As of August 11, 2026, approximately 10:06 a.m. ET

bitcoin price~$64,146
Sats per dollar~1,559
Block height962,013
Recommended next-block fee2 sat/vB
Three-day network hashrate~896 EH/s
Projected next difficulty adjustment-2.61%
Next retarget height963,648
US spot ETF flow, Aug. 10-$144.67M
US spot ETF assets, Aug. 10~$78.16B

Sources: Kraken for spot price; mempool.space for block, fee, hashrate and difficulty data; TFTC Bitcoin ETF Flows for ETF data through Aug. 10.

TFTC Roundtable

Criminals do not respect AI guardrails. Law-abiding defenders should not be constrained by them.

Join the Roundtable

⚡ Open-source security needs funded maintainers, clear disclosure channels and tools that defenders can actually use.
Browse BitcoinProducts.com

See you tomorrow. This is not investment advice. Do your own research.


YouTube: https://www.youtube.com/@TFTC

podcast: https://www.tftc.io/tag/podcasts/

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.