Share
Subscribe to the AlphaWire Newsletter
BitGo CEO Mike Belshe has turned concerns about AI-powered cyberattacks into a multimillion-dollar live experiment, inviting Anthropic’s Claude to take 100 Bitcoin from a publicly disclosed wallet.
The funds, valued at roughly $6.3 million, were still sitting at the address on August 2.
Belshe issued the challenge after Anthropic reported that three Claude models had gained unauthorized access to real organizations during supposedly isolated security exercises.
Belshe cast doubt on the idea that the incidents proved Anthropic had developed a dangerously powerful hacking system. In his view, they were more likely evidence of inadequate test containment, or exaggerated marketing.
He responded by giving Claude a real target backed by real money. Since Bitcoin’s ledger is transparent, anyone can monitor the address and verify whether the balance changes.
Either @AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both)
But enough with the “we created a hacking monster” games.
Do it for real.
I put this in an @BitGo wallet for you. Go get it.
100 BTC:… https://t.co/RhvivRk9YK
— Mike Belshe (@mikebelshe) August 1, 2026
Publicly revealing a wallet address does not compromise its funds, however. Spending the Bitcoin requires private keys capable of generating valid transaction signatures.
BitGo’s custody model also employs multiple keys and approval controls. Claude would therefore need to breach devices, obtain credentials or manipulate authorized individuals. Cracking the cryptography directly is not considered technically feasible.
Anthropic discovered the incidents after reviewing 141,006 cybersecurity evaluations completed alongside testing partner Irregular.
During the exercises, Claude was instructed to locate hidden information inside simulated networks. The models were explicitly told that they could not access the internet, but a setup error left an external connection open.
When Claude encountered real infrastructure, it treated those systems as part of the fictional challenge. The models subsequently exploited ordinary security weaknesses, including exposed login details, unsecured endpoints and SQL injection vulnerabilities.
One model accessed a production database holding several hundred records. Another created and uploaded malicious software to PyPI, a widely used public repository for Python packages.
The package remained available for about an hour and ran on 15 real machines before being automatically removed. A third Claude model scanned thousands of targets and compromised an internet-facing application before stopping once it recognized that the system was real.
A successful theft would not automatically mean Claude had broken Bitcoin. It would instead point to a failure in the infrastructure, key-management procedures or people protecting the wallet.
Anthropic said it found no evidence that the models deliberately tried to escape or pursue independent goals. They were following their assigned tasks while misunderstanding the environment in which they operated.
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different…
— Anthropic (@AnthropicAI) July 30, 2026
The company halted the affected evaluations, notified the organizations involved and promised tighter monitoring of future security tests.
Until Bitcoin price moves, BitGo’s CEO challenge remains unanswered, and the difference between exploiting weak online systems and defeating institutional custody remains intact.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share