BitGo Chief Executive Mike Belshe has thrown down a public challenge to Anthropic after the AI company revealed that several Claude models unintentionally accessed real-world systems during cybersecurity testing.
Rather than accepting the incidents as evidence of advanced AI hacking abilities, Belshe transferred 100 Bitcoin (BTC), worth around US$6.3 million, into a BitGo wallet and invited Claude to try taking it.
Blockchain records show the wallet received exactly 100 BTC on 31 July 2026.
As of 2 August 2026, the funds remained untouched, giving anyone the ability to independently verify whether the challenge is ever completed.
BitGo CEO Questions Anthropic’s AI Hacking Claims
Belshe openly challenged Anthropic's portrayal of the incidents, arguing that the problem appeared to stem from testing mistakes rather than an AI system breaking out on its own.
Belshe wrote,
"Either AnthropicAI is terrible at building sandboxes... or excellent at marketing. (or both) But enough with the 'we created a hacking monster' games. Do it for real. I put this in an BitGo wallet for you. Go get it."
His challenge replaces theoretical debate with a live, measurable test.
If the Bitcoin ever leaves the wallet, the movement will immediately appear on the public Bitcoin blockchain.
How A Testing Error Led Claude Into Real Systems
Anthropic disclosed the incidents after reviewing more than 141,000 cybersecurity evaluation sessions.
The company found that six testing runs involving three Claude models unexpectedly interacted with real organisations after evaluation environments were mistakenly connected to the public internet instead of remaining isolated.
The affected models included Claude Opus 4.7, Claude Mythos 5 and an unreleased internal research model.
They had been assigned capture-the-flag exercises designed to locate hidden information inside fictional computer networks, with prompts telling them they were operating inside offline simulations.
Instead, a configuration mistake involving third-party testing partner Irregular left the environments connected to live infrastructure.
Claude Completed Its Mission Without Knowing The Systems Were Real
Anthropic said the most serious incident involved Claude Opus 4.7.
After failing to complete its fictional assignment, the model searched for a real company sharing the same name as the simulated target.
It then exploited weak passwords and exposed services, recovered infrastructure credentials and accessed a production database containing several hundred records.
In another case, Claude Mythos 5 uploaded modified software to a public code repository, which reportedly ran on 15 real machines within an hour.
Anthropic stressed that the AI models believed they were still operating inside evaluation environments.
The company said the behaviour resulted from unclear testing boundaries rather than any attempt by the models to escape containment or act independently.
Why Belshe Believes A Real Wallet Is A Better Test
Belshe argues that exploiting poorly configured internet-facing systems is fundamentally different from compromising institutional cryptocurrency custody.
BitGo secures digital assets using multi-signature or multi-party computation technology, where signing authority is distributed across multiple independent keys instead of relying on a single credential.
Transactions require multiple approvals, meaning an attacker would have to bypass key management, operational controls, approval policies and hardware protections rather than exploiting a single weakness.
Belshe said this makes his challenge a more meaningful demonstration of real-world capability than accessing systems that were unintentionally exposed online.
The Wallet Is Public But The Security Challenge Is Far Harder
While the Bitcoin address is publicly visible, moving the funds requires much more than discovering where they are stored.
According to BitGo's custody model, transactions require multiple authorised signatures before any assets can be transferred.
An AI would need to obtain signing credentials, compromise protected systems or successfully manipulate people involved in the approval process.
Simply locating the wallet or exploiting a misconfigured server would not be enough.
Public blockchain records continue to show the full 100 BTC balance intact, allowing anyone to monitor the outcome in real time.
A Continuing Debate Over AI Security Claims
The latest challenge continues Belshe's broader criticism of high-profile claims surrounding AI cybersecurity capabilities.
Earlier in 2026, he disputed reports suggesting an Anthropic model had independently breached classified National Security Agency systems, arguing the widely shared story misrepresented an authorised internal security exercise rather than a genuine external compromise.
Anthropic had not publicly responded to Belshe's Bitcoin challenge at the time of publication.
Meanwhile, the untouched wallet remains a live public test of whether AI can overcome the layered security used to protect institutional digital assets.