

The Web3 industry is facing a new kind of arms race. As artificial intelligence advances at a relentless pace, the battle between blockchain defenders and malicious cyber actors has shifted to a new battleground: access to frontier AI models. Highly sophisticated AI systems capable of auditing code and identifying zero-day exploits have become the ultimate defensive tool, yet only a privileged few crypto organisations have been granted access to them.
This growing disparity is creating an alarming security divide across the cryptocurrency ecosystem, placing billions of dollars in digital assets at risk.
Frontier AI developers, such as Anthropic and OpenAI, have adopted cautious, tiered rollout strategies for their most capable cybersecurity models. Anthropic’s restricted model, known as Mythos, shares the same foundational architecture as its public Fable model but operates without the safety guardrails that usually prevent deep cybersecurity probing and automated code exploitation. Similarly, OpenAI reserves specialised iterations like GPT-5.5 with 'Trusted Access for Cyber' for verified defenders, while limiting more permissive penetration-testing versions to an even smaller group.
Model creators argue that restricting these tools is initially essential. If an advanced model enhances offensive capabilities faster than defensive ones, releasing it to the general public could cause widespread damage. By limiting access to controlled testing environments—such as Anthropic’s Project Glasswing—developers aim to reduce the potential impact while evaluating how these systems perform in real-world scenarios.
While model developers maintain gated access to protect the public, security leaders across the crypto space warn that this friction is putting legitimate projects in severe danger. The key issue lies in the rapid evolution of open-source AI models. As publicly available AI models grow increasingly powerful, attackers are gaining access to offensive intelligence without needing official permission.
This imbalance is already yielding real-world consequences:
When malicious actors leverage rapidly improving open-source tools while legitimate defenders wait for clearance to use top-tier protective AI, the ecosystem becomes dangerously vulnerable.
Surprisingly, even the largest and best-capitalised entities in Web3 are struggling to secure access to restricted models. Binance, the world's largest cryptocurrency exchange by trading volume, holding over $130 billion in user assets, has been unable to obtain access to frontier cybersecurity models like Mythos.
Similarly, major custodians such as Fireblocks—which secures trillions of dollars in transactions annually—and decentralized finance pioneers like Uniswap have faced hurdles or restrictions when seeking access to unrestricted cyber models.
Instead, early access has primarily gone to traditional financial technology providers and cybersecurity firms, such as FIS and HackerOne, through specialised defensive initiatives like Project Glasswing. While these partnerships strengthen underlying infrastructure, Web3 protocols that manage smart contracts and decentralized liquidity remain largely excluded from the primary defensive line.
Security executives across the blockchain ecosystem are calling for streamlined verification programmes to get state-of-the-art defensive AI into the hands of legitimate developers much faster.
While initial caution is understandable, prolonged gating becomes counterproductive once open-source models reach comparable capability thresholds. Broadening access ultimately favours defenders because the global community of ethical security researchers, white-hat hackers, and protocol developers vastly outnumbers malicious actors. Giving good actors AI tools that multiply their defensive capacity creates a net positive for the entire ecosystem.
Until AI developers open up faster approval pathways for Web3 defenders, crypto protocols must double down on multi-layered security practices, continuous auditing, and rigorous bug-bounty initiatives to stay ahead of automated threats.
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
