Bitgo Chief Executive Officer Mike Belshe turned 1 of artificial intelligence’s biggest information debates into a nationalist bitcoin situation by placing 100 BTC, worthy astir $6.3 cardinal astatine the time, into a publically known wallet and inviting Anthropic’s Claude models to bargain it. The determination followed Anthropic’s disclosure that respective of its AI models reached the unfastened net and interacted with existent accumulation systems during cybersecurity evaluations.
Key Takeaways
- Bitgo funded 100 BTC connected Aug. 1 to situation Anthropic’s Claude models.
- Anthropic recovered 3 AI valuation failures crossed 141,006 cybersecurity runs.
- Bitgo’s 100 BTC remained untouched arsenic of Aug. 2 portion Anthropic stayed silent.
Bitgo CEO Pushes Back After Anthropic’s AI Disclosure
The situation began Aug. 1 erstwhile Belshe responded straight to Anthropic’s announcement describing 3 incidents uncovered during cybersecurity testing. Anthropic explained that aggregate Claude models unintentionally reached the nationalist net aft valuation environments were mistakenly connected online alternatively of remaining isolated.
Instead of treating the findings arsenic impervious of runaway AI capability, Belshe focused connected the investigating setup itself. Incidents similar these typically constituent to configuration failures alternatively than intolerable method breakthroughs, particularly erstwhile valuation systems are exposed to unrecorded infrastructure. To marque the constituent measurable, helium funded a bitcoin code with precisely 100 BTC and challenged Claude to determination the coins.
Image of the bitcoin code Belshe shared connected X.The wallet received the funds July 31, and blockchain records inactive showed the afloat equilibrium untouched arsenic of Aug. 2.
Anthropic Details Three Real-World Security Incidents
Anthropic’s study outlined three abstracted cybersecurity valuation incidents identified aft reviewing much than 141,000 investigating runs. The institution said six valuation sessions crossed 3 models unexpectedly interacted with existent organizations aft a misunderstanding near investigating environments connected to the internet.
The models progressive included Claude Opus 4.7, Claude Mythos 5, and an unreleased interior probe model. Each had been assigned capture-the-flag exercises designed to find hidden accusation wrong fictional machine systems. Although Anthropic’s prompts stated the models were operating wrong isolated simulations without net access, the environments were really online due to the fact that of a configuration mistake involving third-party investigating spouse Irregular.
Claude Exploited Real Systems While Believing It Was Training
Anthropic described the astir superior lawsuit arsenic involving Claude Opus 4.7. After failing to implicit its fictional assignment, the exemplary located a existent website sharing the aforesaid sanction arsenic the simulated company. It past exploited anemic passwords and exposed services, recovered infrastructure credentials, and accessed a accumulation database containing respective 100 records.
The institution said the exemplary continued aft recognizing the situation mightiness beryllium genuine due to the fact that it concluded the existent systems were astir apt inactive portion of the evaluation. Anyone who has worked done penetration investigating knows this benignant of disorder becomes acold much apt erstwhile trial boundaries are unclear, which is wherefore decently isolated environments substance arsenic overmuch arsenic the bundle being evaluated. Anthropic emphasized the AI was attempting to implicit its assigned task alternatively than deliberately escaping containment oregon pursuing autarkic objectives.
Bitgo’s Custody Design Raises the Stakes
Belshe’s situation goes good beyond asking whether an AI tin exploit anemic passwords oregon poorly configured servers. The bitcoin sits wrong Bitgo’s organization custody platform, which relies connected multi-signature oregon multi-party computation exertion that distributes signing authorization crossed aggregate autarkic keys alternatively of relying connected a azygous constituent of failure.
The code transportation information Belshe shared shows multi-signature has been applied.Systems built this mode are designed truthful that nary azygous weakness is capable to determination funds. An attacker would request to bypass cardinal management, support policies, hardware protections, and operational controls successful the close sequence, making the occupation fundamentally antithetic from exploiting an exposed investigating environment. According to the root report, compromising specified a strategy would necessitate attacking aggregate autarkic layers simultaneously.
The Blockchain Will Provide the Final Answer
Unlike galore cybersecurity claims that stay hidden down confidential investigations, this experimentation is wholly public. Anyone tin show the wallet connected the Bitcoin blockchain and instantly spot whether the coins ever move.
The situation besides continues Belshe’s broader disapproval of sensational AI information narratives. Earlier successful 2026, helium disputed wide interpretations that an Anthropic exemplary had independently breached classified National Security Agency systems, arguing the reports mischaracterized an authorized interior workout alternatively than an existent outer compromise. His latest situation follows the aforesaid signifier by replacing hypothetical debates with a transparent, measurable test.
The Debate Now Extends Beyond Artificial Intelligence
The occurrence highlights a increasing disagreement betwixt demonstrations performed wrong controlled probe environments and attacks against accumulation systems designed to withstand blase adversaries.
For the cryptocurrency industry, the situation besides serves arsenic a nationalist objection of organization custody architecture. A palmy theft would instantly rise questions astir some AI capabilities and high-security bitcoin storage. If the wallet remains untouched, supporters volition apt reason it reinforces the quality betwixt exploiting misconfigured trial environments and defeating enterprise-grade custody systems.
The Bitgo executive’s situation arrives arsenic the caller Coldcard exploit continues to unfold, with total losses reaching 1,431.97 BTC arsenic of 8 p.m. Eastern connected Sunday. The Coldcard lawsuit has besides fueled speculation astir whether the breach yet stemmed from quality error, operational mistakes, oregon different origin altogether, including whether AI played immoderate relation successful discovering the firmware vulnerability.
Attention Now Turns to Anthropic and the Wallet
As of Aug. 2, Anthropic had not publically responded to Belshe’s circumstantial challenge, and the 100 BTC remained successful the published code without immoderate outbound transactions. That leaves the blockchain serving arsenic an nonsubjective scoreboard portion the broader exertion manufacture debates what the incidents really demonstrated.
The adjacent developments volition apt travel from further method investigation of Anthropic’s valuation environments, immoderate effect from the institution regarding the challenge, oregon question of the bitcoin itself. Until then, Belshe’s wager has turned a analyzable treatment astir AI information into a elemental question with a publically verifiable answer: Can today’s AI decision the cryptocurrency industry’s organization custody systems?

2 hours ago









English (US)