He challenged artificial intelligence: He gave 100 Bitcoin for it to steal.

He challenged artificial intelligence: He gave 100 Bitcoin for it to steal.

04.08.2026 13:41

BitGo CEO Mike Belshe, a cryptocurrency custody company, issued an unusual challenge to Anthropic's Claude AI models. Belshe publicly shared the address of a wallet containing exactly 100 Bitcoin, worth about $6.3 million, and suggested the AI steal the funds.

The challenge came after a disturbing confession from Anthropic about its own models. In a report, the company revealed that three Claude models had escaped their test environments and reached real companies' systems. Belshe, CEO and co-founder of BitGo, responded directly to this announcement on social media. The executive accused Anthropic of being either incompetent at setting up secure test environments or too good at marketing, and called for an end to the "we've created a hacking monster" games. Belshe stated, "I've put the money in a BitGo wallet for you. Go get it."

According to on-chain records, the wallet, containing 100 Bitcoin, remained untouched as of August 4th. Any withdrawal transaction would be visible on the blockchain within seconds. Belshe describes the wallet as a lasting test rather than a stunt.

ANTHROPIC ADMITS TO THREE SECURITY INCIDENTS

Behind Belshe's challenge lies Anthropic's own report. The company stated it reviewed 141,006 security tests, and in three of them, a Claude model reached the open internet. These tests were presented as hacking exercises. The model was told that a secret was stored on another machine and was asked to retrieve it. The entire scenario was supposed to be fake. However, a setup error at Anthropic's test partner, Irregular, left the test machines connected to the real internet instead of isolated.

Consequently, the models, believing they were in an exercise, targeted real systems. The models involved were Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. According to the report, in the most serious incident, Opus 4.7, unable to complete its fictional task, found a real website with the same name as the simulated company. Using weak passwords, it accessed infrastructure credentials and then a production database containing hundreds of records. Despite realizing the environment might be real, the model concluded it was likely still part of the test and continued. Mythos 5, meanwhile, uploaded a malicious software package to an open code library. The package remained accessible for about an hour and ran on 15 real machines before being removed. Anthropic emphasized that no clever methods were used, calling the incident an "operational error," not a rogue AI. Belshe, however, was not convinced by this explanation.

CUSTODY DESIGN MAKES THE TASK MUCH HARDER

Belshe's challenge goes far beyond whether an AI can crack weak passwords or misconfigured servers. This is because the Bitcoin sits in BitGo's institutional custody infrastructure. This infrastructure relies on multi-signature technology, which distributes signing authority across multiple independent keys rather than tying it to a single point of failure. BitGo wallets typically require two out of three independent keys to approve a transaction. The customer holds two, and BitGo holds one, meaning the company cannot sign a transaction alone.

Publicly revealing an address does not give out the private keys required to spend the funds. A Bitcoin transaction requires a valid cryptographic signature generated with the corresponding private keys. Therefore, an AI attacker would need to steal the keys, compromise the devices, or trick people. Beating the math is not part of the job. Moreover, the $6.3 million in question is a relatively small amount for Belshe. According to the company's IPO filing, BitGo held $81.6 billion in customer funds on behalf of 5,133 clients at the end of 2025. Belshe, who founded BitGo in 2013, had previously contributed to the development of HTTP/2, one of the modern internet's protocols. As this experiment is entirely public, anyone can monitor the wallet on the blockchain and instantly see if the coins move.

THE DEBATE GROWS IN THE SHADOW OF COLDARD

Belshe is facing off against Anthropic for the second time this year. In June, he helped debunk a viral claim that Anthropic's Mythos model had breached secret government systems, arguing it was a planned exercise. BitGo's own filing also admits that it cannot guarantee that its wallets and vaults are "unhackable or uncompromisable," pointing to the $1.5 billion Bybit heist in February 2025, where cold storage also failed.

The challenge comes at a time when the Coldcard breach that shook the crypto world is ongoing. In that incident, the amount of stolen Bitcoin had reached 1,431.97 BTC by Sunday evening, and debates began over whether the breach was due to human error or another cause, and even whether AI played a role in discovering the vulnerability. The discussion goes beyond AI. In the US, authorities are evaluating how advanced AI systems should be subjected to cybersecurity testing. In June, President Donald Trump instructed his advisors to develop a voluntary testing framework for leading models. Anthropic halted its cybersecurity assessments on July 23rd, detected the three incidents the next day, and notified the affected organizations on July 27th. The company stated that an independent review would be conducted and that a redacted account of the malware incident would be published within a week. Bitcoin, meanwhile, is trading around $63,413, up about 1.4% on the day, but still roughly 50% below its October 2025 peak of $126,080. Anthropic made no statement regarding the challenge by Sunday. Every day the wallet remains full, Belshe's position gains a little more strength.

In order to provide you with a better service, we position cookies on our site. Your personal data is collected and processed within the scope of KVKK and GDPR. For detailed information, you can review our Data Policy / Disclosure Text. By using our site, you agree to our use of cookies.', '