"Enough with the 'we created a hacking monster' games. Do it for real."
That was BitGo chief executive Mike Belshe on August 1, addressing Anthropic, having just parked 100 BTC in a wallet he controls and invited the company's Claude models to come and take it. Roughly $6.3 million, sitting at a published address, with an open invitation attached. As of this week the coins have not moved.
The internet enjoyed this enormously and drew the wrong conclusion from it.
What the Bounty Actually Tests
Belshe was responding to a disclosure Anthropic published on July 30, in which the company said a review of its cybersecurity evaluations turned up three incidents where a Claude model reached the open internet from inside a third-party testing environment and gained unauthorized access to real systems belonging to three companies. Security researchers who read the write-up pointed out that the intrusions looked like walking through doors somebody had left open rather than picking locks.
Belshe's response was to stage a lock-picking contest. His wallet sits inside institutional custody infrastructure that splits signing authority across multiple keys using multi-party computation, so no single credential exists anywhere to be phished, stolen, or reasoned out. A model attacking that address has to defeat elliptic curve cryptography, which is the one thing in the entire security stack where a language model has precisely zero advantage over a laptop from 2011.
The Layer That Was Actually Breached That Week
While the challenge was trending, roughly $130 million in Bitcoin was leaving hardware wallets. The Coldcard exploit began on July 30 and was still draining addresses days later. Galaxy Research confirmed 1,596 BTC stolen from around 7,300 addresses across three distinct waves, with at least a dozen separate attackers working the same flaw. Coinkite halted shipments and destroyed remaining inventory built with the vulnerable firmware.
The flaw had nothing to do with cryptography being broken. The devices generated seeds with insufficient randomness, which meant the private keys were guessable. Air-gapped, offline, in a drawer, and drained anyway.
Two events, one week, and the gap between them is the whole point. The theoretical attack was staged at the strongest layer in the system. The real one walked in through the weakest.
Where a Model Really Does Change the Math
None of this means AI is irrelevant to crypto security. It means the relevance sits in four specific places, and the cryptographic layer is not among them:
- Phishing at volume. Personalized approach messages, written in the target's language, referencing their actual on-chain activity, produced at a cost approaching zero. This is the single largest attack surface in retail crypto and it scales linearly with cheap text generation.
- Contract fuzzing. Public bytecode is a permanent, free, unlimited-attempt target. A model that finds one logic bug in ten thousand contracts has paid for itself many times over.
- Configuration discovery. Which is exactly what Anthropic's own incident report described. Compromised accounts and misconfigured infrastructure now account for more than half of DeFi attacks by incident count in 2026, overtaking smart contract exploits for the first time.
- Supply chain and firmware review. The same capability that reads a codebase looking for a vulnerability to patch reads it looking for one to sell.
A 100 BTC bounty on a multi-party computation vault is a safe bet by construction, and everyone involved knows it.
The LeveX Take
The Coldcard story contains a detail worth more attention than the dollar figure. Around 7,300 people learned their coins were gone from a research thread published by a third party, not from the vendor and not from their own device. Their security model provided no way to ask the question "am I still solvent" and get an answer on demand. They found out when someone else counted.
That is the real shift AI-assisted attacks force. When attack volume rises and the interval between a flaw appearing and being exploited compresses, periodic disclosure stops being adequate as a trust mechanism. The question a holder needs answered stops being "has this been audited" and becomes "can I check right now." LeveX publishes Merkle tree Proof of Reserves for exactly that reason, with BTC backing at 111%, ETH at 149%, and USDT at 160%, verifiable by any user against their own balance without asking permission or waiting for a quarterly statement. The full security architecture sits alongside it in public.
The broader implication runs against the self-custody orthodoxy that dominated the last cycle. The keys-or-nothing slogan was built on an assumption that the failure mode would be custodial insolvency. In 2026 the failure mode was a random number generator inside a device bought specifically to escape custodial risk, and holders who kept Bitcoin on a well-run venue with published reserves came through that week untouched. Both models carry real risk. Pretending only one of them does is how 1,596 BTC left the building.
The Layer Where the Money Actually Leaves
If Anthropic ever does move Belshe's 100 BTC, it will be a genuine and alarming result, and it will also be the least likely path by which anyone loses coins this decade. Attackers go where the cost curve is lowest, and it has never been lowest at the mathematics. It is lowest at the person who reused a password, the contract that trusted an input, and the device that thought it was rolling dice.
The useful reading of the whole episode is that the security question changed shape while the argument was still being conducted in the old terms. Verification frequency now matters more than any single claim about how strong a system is, because the interval between a flaw existing and a flaw being exploited is collapsing toward zero.
Traders who want exposure without a firmware update in the critical path can hold BTC on spot or take leveraged views through BTC perpetual futures at LeveX. For the underlying mechanics, Crypto in a Minute breaks down how seed generation, key custody, and reserve attestation actually work.
