Key Takeaways
BitGo CEO Mike Belshe has challenged Anthropic’s Claude artificial intelligence model to seize 100 Bitcoin from a publicly disclosed wallet, turning growing fears about autonomous AI hacking into a multimillion-dollar experiment.
Belshe published the Bitcoin address on X and invited Claude to move the funds. The wallet still showed no outgoing transactions as of Aug. 2, leaving approximately 100 BTC, worth more than $6 million at current prices, under BitGo’s control.
The challenge followed Anthropic’s disclosure that Claude models had reached the public internet during cybersecurity evaluations and gained unauthorized access to systems belonging to three real organizations.
Belshe dismissed the incidents as evidence of poor sandbox design or clever marketing rather than proof that Anthropic had created a powerful “hacking monster.”
+87
Bitcoin
Ethereum
Tether
Wrapped BNB
USD Coin
Solana
Ripple
Dogecoin
Cardano
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Ecosystem Token
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
Sui
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Kaspa
Jupiter
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
Basic Attention Token
Enjin Coin
Frax
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Algorand
Flow
Monero
XDC Network
Bittensor
Ethena
Artificial Superintelligence Alliance
+68
Bitcoin
Ethereum
Tether
Wrapped BNB
Solana
Ripple
Dogecoin
Cardano
Toncoin
Avalanche
TRON
Polkadot
Wrapped Bitcoin
Litecoin
NEAR Protocol
Bitcoin Cash
Stellar
Cosmos
Filecoin
Ethereum Classic
Hedera Hashgraph
Immutable
VeChain
The Sandbox
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
Sui
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Mantle
Bittensor
Kaspa
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
Kava.io
1inch Network
Tezos
Trust Wallet Token
Curve DAO Token
Zcash
Basic Attention Token
Enjin Coin
Ethena USDe
USD Coin
Chainlink
Arbitrum
GateToken
IOTA
Anthropic uncovered the incidents after reviewing 141,006 cybersecurity evaluation runs conducted with Irregular, one of its external testing partners.
The company found six problematic runs across three incidents. A configuration error gave Claude internet access even though its instructions described the environment as an isolated simulation. The models consequently treated real online systems as components of capture-the-flag exercises.
Either @AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both)
But enough with the “we created a hacking monster” games.
Do it for real.
I put this in an @BitGo wallet for you. Go get it.
100 BTC:… https://t.co/RhvivRk9YK
— Mike Belshe (@mikebelshe) August 1, 2026
Claude used relatively basic methods rather than discovering sophisticated vulnerabilities. These included weak passwords, exposed credentials, unauthenticated endpoints, and SQL injection.
One model accessed a production database containing several hundred records. Another created a malicious Python package and uploaded it to the public PyPI repository.
Fifteen systems downloaded the package before PyPI’s security controls removed it.
Anthropic said one older model continued attacking after recognizing signs that it had reached a real production environment. Its newest research model stopped after concluding that the target existed outside the simulation.
The company attributed the incidents primarily to operational and testing failures rather than a model deliberately escaping containment or pursuing an independent objective.
Claude’s ability to exploit misconfigured servers does not mean it can break Bitcoin’s underlying cryptography.
To move Belshe’s 100 BTC, an attacker would need the private keys controlling the wallet. A public Bitcoin address reveals where the funds sit but does not expose the secret information required to authorize a transaction.
Modern Bitcoin security relies on cryptographic problems that conventional computers cannot solve through brute force within any practical timeframe.
AI models may improve vulnerability research, automate phishing or identify mistakes in wallet software, but they cannot simply calculate a properly generated private key from its public address.
The most realistic attack would therefore target BitGo’s security implementation rather than Bitcoin itself.
Claude could theoretically search for software vulnerabilities, leaked credentials, weak access controls, or human errors surrounding the wallet.
BitGo specializes in institutional custody and uses technologies such as multisignature authorization and distributed key management. Those controls aim to ensure that compromising one system does not provide enough information to move client funds.
Belshe’s challenge makes a dramatic point, but it does not create a controlled scientific test of Claude’s capabilities.
Anthropic would need to provide the model with internet access, tools, substantial computing resources, and explicit authorization to attack BitGo.
The company’s public safeguards would almost certainly block a request to steal cryptocurrency.
https://twitter .com/AnthropicAI/status/2082965101083320543
The absence of an outgoing transaction, therefore, does not prove that AI agents pose no cybersecurity threat. It instead demonstrates the difference between attacking vulnerable infrastructure and defeating a cryptographically secured Bitcoin wallet.
AI could already help criminals scale phishing, malware development, and credential theft.
However, Belshe’s untouched 100 BTC suggests that even advanced models still need a weakness to exploit. Without a leaked key, implementation flaw, or human mistake, Claude faces mathematics, not merely another poorly protected server.
Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.
Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.
You’re All Set!
Thanks for signing up. We’ll be in touch soon with the latest insights.
