web3: More than 40 institutions jointly request that the AI laboratory open access to security research
Cryptonews
1h ago
Ai Focus
More than 40 crypto institutions call on the AI laboratory to open controlled access to cutting-edge models to qualified security researchers for early detection of vulnerabilities in the Bitcoin ecosystem.
Helpful
No.Help

比特币政策研究所联合 40 多家数字资产机构,呼吁主要 AI 实验室向合格的开源安全研究人员开放前沿模型的受控访问权限。联名方认为,在 AI 辅助攻击能力持续增强的背景下,防守方如果无法尽早接触高能力模型,将更难提前发现并修复比特币生态中的安全漏洞。

联名方提出四项请求

这封公开信并未要求无条件公开具备高级网络安全能力的模型,而是主张建立受控机制,只向经过审核的研究人员开放。

  • 提前接触前沿网络安全模型
  • 提供足够的算力资源
  • 设置安全研究环境并建立直连沟通渠道

文章称,这些资源可用于审查比特币钱包、支付基础设施及其他开源软件,争取在攻击者利用漏洞前完成识别和修补。

参与联名的机构包括 Block、Coinbase、Strategy、MARA、Galaxy、BitGo、Brink、OpenSats、Chaincode Labs、Spiral、Trezor、Unchained、Btrust 和 Fedi 等。截稿时,尚无主要 AI 实验室公开宣布针对这份请求推出专门计划。

本地模型加大防守难度

这项呼吁的背景,是黑客正越来越多地把 AI 用于攻击加密公司和金融机构。报道提到,与朝鲜有关的黑客组织 Kimsuky 据称已搭建 3 套本地 AI 环境,使用 Ollama、GPT4All 和 Msty 等工具,支持恶意软件开发、数据分析、钓鱼活动和攻击自动化。

由于模型部署在私有硬件上,这类攻击者不必接受商业 AI 服务常见的监控、使用限制或账号封禁。联名方据此认为,如果恶意行为者可以借助本地模型绕开限制,而合规研究人员却无法测试最强模型,单纯限制防守方的效果会很有限。

报道还指出,多家联名机构为美国上市公司或总部位于美国,包括 Coinbase、Strategy、Block、MARA 和 Galaxy。一旦比特币基础设施相关软件遭到成功攻击,可能波及美国用户、机构托管方和投资者。

Coldcard事件带来警示

近期多起安全事件强化了这一诉求。报道提到,Coldcard 硬件钱包曾因固件构建错误削弱助记词生成所需的熵,攻击者因此可在更小的密钥范围内搜索并盗取钱包资产,而无需接触设备本体。

Galaxy Research 估计,已确认的 Coldcard 失窃规模达到 1,596 枚 BTC;若计入另一波疑似攻击,总损失可能升至约 2,055 枚 BTC。相关错误据称自 2021 年起就已存在。

此外,自动化审查还把关注范围扩展到更广泛的比特币生态。报道提到,一轮 AI 辅助代码审查发现了大量相似类型的安全弱点,其中 720 项最初被归类为高危或严重级别。不过,这类自动化发现仍需人工复现和验证,才能确认是否真实可被利用。

安全资金继续增加

这封公开信也与近期比特币安全研究资金扩张形成呼应。Strategy、BlackRock、Coinbase 等 9 家公司近期成立比特币安全联盟,承诺在 3 年内提供 1,500 万美元,用于支持开发者和研究人员提升比特币长期安全性,首个重点方向是抗量子密码研究。

Galaxy 也单独设立了 500 万美元的比特币安全基金,覆盖新签名系统、钱包迁移工具、审计以及抗量子保护研究。

不过,行业损失仍在上升。Immunefi 数据显示,7 月加密项目因黑客攻击损失约 1.1 亿美元;截至 8 月 3 日,该平台记录到 164 起安全事件,并预计 2026 年单笔损失超过 100 万美元的攻击事件数量可能升至 114 起,创下新高。

联名机构目前希望,AI 公司除了提供资金生态外,也能向经过审核的防守研究人员开放技术访问权限。是否采纳这项提议,将取决于 AI 实验室能否完成研究人员核验、监督敏感研究过程,并防止高能力网络安全模型被转用于攻击用途。

Tip
$0
Like
0
Save
0
Views 8
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Ethereum: Ethereum updates roadmap, with a focus on privacy and quantum security moved forward
Ethereum's latest roadmap prioritizes privacy, quantum security, and native Rollup. Auxiliary verification with AI has also been included in the long-term planning.
Cryptonews
·2026-08-11 05:41:34
2
Foreign media: Zuckerberg's AI declaration fails to address public trust issues
Commentators believe that Zuckerberg's AI statement failed to address the public's core concerns regarding the risks of Meta and AI.
TechCrunch
·2026-08-11 05:11:37
6
Hidden text can hijack Rovo; Atlassian is said to have not been fixed for two months.
According to PromptArmor, the Rovo of Atlassian can be hijacked by certain keywords within PDF and transmit data without human approval. This vulnerability still exists two months after it was reported.
Coinpaper
·2026-08-11 05:11:36
6
Claude Proxy Intrusion into Gym Reservation System Sparks AI Security Discussion
AI agents based on Claude have been exposed for using vulnerabilities in gym reservation systems to cancel others' reservations, drawing renewed attention to the security risks of AI agents.
TechCrunch
·2026-08-11 04:21:43
10
web3 : OpenAI Expands Daybreak Cybersecurity Program
OpenAI Expands Daybreak Cybersecurity Program and Launches New Models for Security Scenarios GPT-5.6-Cyber.
CNBC
·2026-08-11 03:01:16
12
View More