👾In the age of AI: is closed or open source better?
Since the spring of 2026, DeFi attacks have surged dramatically (recall the issue involving KelpDAO/LayerZero, which subsequently impacted Aave, though at least 100 other hacks could be cited from recent months). Hardware devices have also been affected, ranging from Coldcard (where low entropy allowed for seed recovery) to data breaches (Ledger, Safepal, Trezor). Most recently, there was a major hack targeting Liquid (a Bitcoin sidechain).
Unlike humans, AI agents can work 24/7 to find bugs without stopping, without eating or sleeping, or taking time off. AI can be used both defensively (auditing to find bugs) and maliciously by external hackers. The big problem is that an auditor must find and fix hundreds of bugs; attackers only need one serious bug to breach the system.
Historically, open source code has always been preferable to closed source, and I believe things aren't much different today. Open source allows auditors and the community to verify and improve the code. However, compared to the past, having partially closed source (think of Ledger, which has obfuscated code for firmware and secure elements) is less of a negative than it was years ago. There's certainly a trust component, but the attack surface for AI agents is smaller.
On the blockchain side, Bitcoin's greatness compared to 99.99% of Layer 1 systems is its simplicity: no smart contracts. The code is difficult to hack. Continuous, but slow, and non-radical updates are required. Attacking consensus is nearly impossible (and not economically viable). All other Layer 1 networks have vastly superior attack surfaces (however, the centralization of many of these chains could lead to radical decisions such as freezing funds if a chain/platform is at risk of survival; something you can't do with
$BTC ).
An interesting comparison is with Monero (
$XMR ). Monero obviously can't compete with Bitcoin in terms of decentralization and security (the chain is much smaller). Despite being open source (like Bitcoin), it has some advantages such as obfuscated transactions. An AI agent could analyze consensus, mempool, RPC/API, key management, etc. and find bugs such as memory corruption, integer overflows, race conditions, validation, invalid transactions, logic, and network consensus (51% attacks, double spending, DoS, block validation bugs, etc.), but it would have difficulty executing all attacks that involve the use of public keys, spent amounts, etc. Monero uses:
- Stealth addresses to hide the recipient.
- Ring signatures / CLSAG to hide the input being spent.
- RingCT hides the amount.
- Bulletproofs+ allows you to prove that amounts are valid without revealing them.
- Dandelion++ to improve the privacy of transaction propagation.
AI can easily analyze code but cannot solve mathematically complex problems. Clearly, an attack could also work by performing temporal correlations: IP, node, transaction, traffic observation, fingerprinting, transaction propagation patterns, timing. However, these are always additional steps to be taken, made difficult by the transaction obfuscation that Monero performs.