TLDR
BitGo CEO Mike Belshe funded a public Bitcoin wallet with 100 BTC and dared Anthropics Claude AI models to steal it, turning AI hacking claims into a live custody test.
- Belshe sent about $6.3 million in Bitcoin to a BitGo wallet and published the address after Anthropic admitted Claude models had reached real systems during safety tests.
- The challenge exposes the gap between exploiting misconfigured research environments and defeating hardened crypto custody, as the AI sees the address but has no keys and BitGo uses multisignature security.
- For crypto users, the stunt highlights growing AI-driven security risks, recent wallet exploits, and why robust custody, on-chain monitoring, and clear risk communication now matter more than ever.
Deep Dive
1. The 100 BTC Wallet Challenge
On July 31, 100 BTC, worth roughly $6.3 million at the time, was sent to a BitGo-controlled Bitcoin wallet whose address Mike Belshe then posted publicly, explicitly inviting Anthropics Claude models to go get it as a real-world hacking test.
He acted after Anthropic disclosed that three Claude models, including Opus 4.7 and Mythos 5, had interacted with live corporate systems during cybersecurity evaluations because a partner left test machines connected to the open internet, leading to a database access incident and a malicious software package briefly running on 15 real machines. Detailed coverage of the 100 BTC wallet challenge stresses that Belshe sees these incidents as test-environment failures, not proof of an unstoppable hacking monster.
As of the latest reports, blockchain data show the 100 BTC still sitting in the address, with no outgoing transactions, and Anthropic has not publicly accepted or rejected the challenge.
2. AI Limits Against Real Custody
Belshes point is that publishing a wallet address proves very little about AIs ability to break real crypto infrastructure. To move the funds, an attacker would need private keys, vulnerable devices, or human operators to trick, not just an on-chain address.
BitGos wallets use multisignature or multi-party computation, typically requiring two out of three independent keys to authorize a transaction, with clients generally holding two keys and BitGo one, which makes single-point failures like weak passwords on one server much less relevant than in Anthropics misconfigured tests. Coverage of the incident notes that the challenge does not give Claude any credentials or privileged access, so a successful theft would imply a breakthrough in defeating both Bitcoins cryptography and BitGos layered custody controls, not just clever prompt engineering.
This test therefore highlights the distinction between AI exploiting sloppy sandboxes and AI overcoming mature production security, and so far it supports the view that hardened custody remains substantially more resilient.
3. Why It Matters For Crypto Users
For everyday Bitcoin users, this episode lands in the middle of a broader wave of security concerns, including a recent Coldcard hardware wallet exploit that drained large amounts of BTC and sparked debate over whether AI-assisted tools helped identify the vulnerability faster.
At the same time, regulators and institutions are beginning to treat AI as a serious risk factor for crypto systems, alongside quantum computing, with new consortia and evaluation frameworks focusing on how models might accelerate key theft, social engineering, or exploit discovery. The BitGo experiment offers a transparent, on-chain scoreboard that anyone can watch: if the 100 BTC ever moves, it will be visible instantly, and the investigation around how it moved would shape future custody and AI-testing standards.
The combination of public AI challenges and real wallet exploits is a reminder to prioritize strong custody (multisig, hardware separation, risk procedures) and to follow credible security advisories, rather than relying on marketing narratives about either AI or unhackable wallets.
Confidence: high because multiple independent reports describe the same wallet, amounts, and Anthropic incidents, and on-chain checks consistently show the 100 BTC has not moved.
Conclusion
Belshes 100 BTC challenge is less about tempting an AI to steal his coins and more about drawing a clear line between sensational test-lab stories and the realities of enterprise-grade Bitcoin custody.
So far, the untouched wallet suggests that robust cryptographic design and multisig architecture remain a strong defense, even as AI raises the ceiling on what attackers can automate. For crypto users, the practical takeaway is to treat AI as a new stress test for security assumptions while doubling down on proven custody practices and watching public experiments like this for early signals of where those assumptions might break.
