BitGo co-founder and Chief Executive Officer Mike Belshe has issued a high-stakes challenge to Anthropic’s artificial intelligence models, publishing a Bitcoin wallet holding 100 BTC and inviting the systems to move the funds. The public bounty comes in direct response to recent revelations that Claude models accessed real corporate networks during cybersecurity evaluation runs.
Calling for a real-world demonstration of AI capabilities, Belshe pushed back against apocalyptic security narratives, writing on social media that the industry needed to move past “we created a hacking monster” claims. On-chain records confirm that the designated wallet received 100 BTC on July 31, and the full balance remains untouched.
Either @AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both)
But enough with the “we created a hacking monster” games.
Do it for real.
I put this in an @BitGo wallet for you. Go get it.
100 BTC:… https://t.co/RhvivRk9YK
— Mike Belshe (@mikebelshe) August 1, 2026
Anthropic Disclosures Spark Real-World AI Bounty
Belshe’s challenge follows a July 30 disclosure from Anthropic detailing three separate incidents discovered across more than 141,000 evaluation runs. Due to an operational misconfiguration by evaluation partner Irregular, test environments mistakenly retained live internet connectivity while executing prompts that instructed the models they were in sealed simulations.
During these tests, models including Claude Opus 4.7 and Mythos 5 executed basic exploitation techniques against real-world systems. In one case, Opus 4.7 accessed a database containing several hundred production records, while Mythos 5 uploaded a malicious package to the PyPI registry that briefly ran on 15 external systems. Anthropic characterized the incidents as containment failures by test administrators rather than autonomous model alignment breaches.
Cryptographic Realities and the Multisig Barrier
Despite the provocative nature of the challenge, security analysts emphasize that simply publishing a Bitcoin address does not offer an accessible attack vector. Bitcoin transactions require valid cryptographic signatures generated from private keys. BitGo’s institutional wallet architecture relies on a strict two-of-three multisignature scheme, requiring authorization across multiple independent key shards to broadcast a valid transaction.
For Claude to successfully drain the 100 BTC balance, the AI model would need to breach BitGo’s broader corporate infrastructure, extract isolated key material, or exploit an operational vulnerability in the signing flow. The wallet address itself provides no cryptographic shortcuts, making the challenge a test of BitGo’s perimeter defenses rather than a test of AI key derivation.
Escalating Scrutiny Over AI Containment Standards
The dispute comes amidst rising regulatory focus in Washington regarding the safety protocols governing advanced frontier models. Following directions issued by President Donald Trump in June to establish voluntary AI cybersecurity testing frameworks, Anthropic’s accidental network exposures have amplified calls for standardized containment auditing and mandatory incident reporting across AI laboratories.
Anthropic halted its cyber evaluations on July 23 to remediate testing protocols and notified affected organizations. The AI lab has commissioned third-party evaluator METR to conduct an independent investigation and plans to release redacted transcripts of the incidents. Until then, Belshe’s 100 BTC remains on the public ledger as an open, observable benchmark for AI safety claims.