TechNewsReel
Live

OpenAI blocks Bitcoin Red Team founder, pushing security research to China

Rob Hamilton's team migrated to Moonshot AI's Kimi K3 after OpenAI revoked access despite the researcher's verification in a 'trust cyber program.'

TechNewsReel Newsroom · August 10, 2026

OpenAI blocked Rob Hamilton, founder of the Bitcoin Red Team, from using its AI security tools on August 9, 2026. The move has forced the security research group to migrate its operations to Chinese models to continue auditing Bitcoin infrastructure.

Hamilton, who also serves as CEO of AnchorWatch, was utilizing AI to conduct security audits of open-source Bitcoin repositories. Despite having completed the required KYC and onboarding for OpenAI's "trust cyber program," his access was revoked. In response, Hamilton and his team shifted their research to Kimi K3, a model developed by the Chinese firm Moonshot AI.

The Bitcoin Red Team's Findings

The project launched following a critical RNG vulnerability in Coldcard hardware wallets in late July 2026. That flaw led to the theft of a significant amount of Bitcoin, prompting Hamilton to assemble a defensive team. The Bitcoin Red Team—comprising Hamilton, a developer known as Calle, and roughly 16 volunteers—spent approximately $20,000 on AI services to secure the ecosystem.

The scale of the effort was immediate and intensive. In the first 30 hours of operation, the team scanned 390 repositories, recording 4,962 total findings. Of these, 85 were classified as critical and 635 as high-severity issues. To mitigate risk, the team employs a "responsible disclosure" practice, notifying repository maintainers of vulnerabilities privately before they can be exploited.

The Conflict Over AI Safety

This incident highlights a growing tension between the safety guardrails implemented by U.S. AI providers and the needs of legitimate cybersecurity researchers. AI safety policies are typically designed to prevent the creation of exploits; however, these same restrictions can hinder defensive research intended to find and fix those exploits before malicious actors do.

For the industry, the consequence is a potential migration of critical infrastructure research toward foreign AI models. When restrictive policies in the U.S. make defensive work untenable, researchers may turn to models from jurisdictions with different oversight standards, such as China. This shift raises urgent questions about whether current "trust programs" are effective or if AI providers are simply unable to distinguish between a threat actor and a security auditor.

What's Next

As the Bitcoin Red Team continues its work via Moonshot AI, the industry will be watching to see if other U.S.-based AI labs refine their verification processes for security professionals. It remains to be seen if OpenAI will establish a more transparent framework for "trust" that allows for high-intensity security auditing without triggering automated safety blocks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.