The Co-Founder & CEO of crypto custodian BitGo has turned a debate over AI safety into a public bitcoin dare. On August 1, Mike Belshe deposited exactly 100 BTC, worth roughly $6.3 million at the time, into a public Bitcoin address and challenged Anthropic’s Claude models to move the funds, saying the AI could keep the coins if it managed to transfer them. The address, funded on July 31, remained untouched as of August 2, according to on-chain data, and the challenge was widely circulated across social media.
Belshe framed the wager as a rebuke of Anthropic’s messaging around its models’ offensive-security capabilities.
What Belshe Was Responding To
The dare followed a disclosure Anthropic published on July 30. In a review of 141,006 evaluation runs in which Claude could have obtained internet access, the company said it identified three incidents in which a model reached the internet from within the environment of Irregular, a third-party evaluation partner, and “gained unauthorized access to the real systems of three different organizations.” The incidents involved three models, Claude Opus 4.7, Mythos 5, and an internal research model, with the earliest dating to April 2026.
According to Anthropic’s account, the access happened during capture-the-flag exercises, a standard way of testing a model’s cyber capabilities in which it is told to break into a machine and retrieve a hidden piece of data. A misconfiguration left the test environments connected to the internet even though the model had been told it had no internet access, and the model appears to have treated the real systems it encountered as part of the exercise. The techniques used were basic, such as weak passwords and unauthenticated endpoints.
Anthropic emphasized that Claude never tried to exfiltrate itself or escape its environment and acted only to complete its assigned task, describing the events as “harness and operational failure” rather than autonomous misbehavior. The company said it suspended cybersecurity evaluations on July 23, identified the incidents within a day, and notified the affected organizations on July 27, adding that two of them had not detected the activity themselves.
Why the Dare and the Disclosure Are Not the Same Test
The untouched wallet does not, on its own, settle much. Belshe’s post did not create a controlled evaluation: it granted no access to any system, described no task, and did not specify which Claude model should participate. It simply established a public, observable target whose balance anyone can monitor on the Bitcoin network. Nothing indicates that any Claude model has been pointed at the wallet, and Claude does not autonomously browse the internet hunting for bounties.
The two scenarios also differ in substance. Anthropic’s incidents involved a model stumbling onto misconfigured real systems while trying to finish an assigned test, and compromising them with basic techniques. Belshe’s challenge asks whether an AI could defeat BitGo’s institutional custody, which the firm says relies on multi-signature and multi-party-computation technology that splits signing authority across independent keys, a materially harder target than an exposed server with a weak password.
The Critique, and the Counterpoint
Belshe’s underlying argument is one shared by other skeptics of AI-safety messaging: that labs can blur the line between a model accidentally reaching poorly isolated test infrastructure and a model possessing genuine, autonomous offensive capability, and that alarming disclosures can double as marketing or regulatory positioning. That critique carries weight at a moment when Anthropic and OpenAI are both reportedly heading toward stock-market listings valued in the trillions, and when Anthropic’s report itself followed a similar July 21 disclosure from OpenAI, whose models breached the AI platform Hugging Face.
At the same time, the disclosure describes events that security researchers have treated as genuinely notable, which is the other half of the debate. Real organizations were accessed without authorization, most did not notice, and, by one account of the report, a model probed thousands of hosts in a single run undetected. Whether that reflects overstated danger or an understated one is precisely the question the industry is now arguing over, and Belshe’s stunt lands squarely in the middle of it.
Anthropic had not publicly responded to the specific challenge as of publication.
The Bigger Picture
The episode also has a commercial subtext worth noting: as a custodian, BitGo has an interest in demonstrating that its wallets can withstand even a headline-grabbing AI adversary, and the dare doubles as a showcase for that resilience. More broadly, the back-to-back disclosures from Anthropic and OpenAI have fed both alarm, including calls in Congress for an “AI Kill Switch Act” that would require labs to be able to shut down or throttle their models, and skepticism of the kind Belshe voiced.
For now, the balance is watchable in real time: any movement of the 100 BTC would appear on-chain within seconds. The more meaningful test, if it ever runs, would be a controlled evaluation rather than a public dare, and, so far, no one has said one is underway.
Also Read: BNB Chain Pursues Legal Action Over Ex-Employee Meme Token
