BitGo CEO Mike Belshe deposited 100 BTC, worth roughly $6.3 million, into a public Bitcoin address on August 1 and dared Anthropic’s Claude to move the funds, telling the AI lab, “enough with the ‘we created a hacking monster’ games.”
The challenge arrives as artificial intelligence companies increasingly demonstrate that frontier models can identify software vulnerabilities, conduct cybersecurity research and operate with greater autonomy.
BitGo turns AI debate into a Bitcoin test
The wager follows heightened attention around Claude’s cybersecurity capabilities and the potential risks associated with deploying increasingly autonomous AI agents.
According to reports circulating around the challenge, Belshe funded a Bitcoin address with 100 BTC and effectively invited Claude to take the coins if it could breach the security protecting them.
The address is publicly visible, allowing the wider crypto community to monitor whether the funds move.
The important distinction is that the challenge does not amount to an attempt to “hack Bitcoin” itself. Bitcoin’s blockchain and its cryptographic rules are separate from the systems used to custody private keys and authorize transactions.
The more relevant question is whether an attacker in this case, an AI agent could compromise the infrastructure surrounding the wallet, obtain the necessary authorization material or exploit an operational weakness that ultimately enables the Bitcoin to be transferred.
The largest losses in crypto have historically tended to emerge from failures around the asset rather than a successful attack on Bitcoin’s underlying consensus mechanism.
BitGo’s institutional custody model is specifically designed to reduce that type of risk. The company says it pioneered multi-signature wallet technology and has developed infrastructure aimed at protecting institutional digital assets.
Belshe’s challenge consequently functions as a public stress test of the broader security stack.
The statement, widely circulated alongside the challenge, captures the confrontational nature of the wager: if AI systems can breach sophisticated digital environments, the CEO of a major crypto custodian is effectively asking them to demonstrate that capability against a target holding real Bitcoin.
Anthropic’s Claude raises the stakes
The challenge comes against a backdrop of increasingly sophisticated cybersecurity capabilities from Anthropic’s Claude models.
Anthropic has publicly acknowledged that the expanding capabilities of AI agents create a corresponding increase in their potential “blast radius.”
In a May 2026 engineering report, the company wrote: “As agents grow more capable, so does their potential blast radius.”
The company has also described the difficulty of safely giving AI agents access to computers, filesystems and networks.
Anthropic says its approach increasingly relies on containment, including sandboxes, virtual machines and network controls, rather than simply asking users to supervise every action.
A conventional chatbot that provides instructions for hacking a wallet is one thing. An autonomous agent capable of browsing, writing code, running tools, analyzing infrastructure and acting on the results represents a fundamentally different security proposition.
Anthropic itself has acknowledged that even carefully designed containment systems can fail in unexpected ways.
Claude’s growing cybersecurity capabilities have also been central to Anthropic’s Project Glasswing initiative.
The company said its cybersecurity model had helped participating organizations identify more than 10,000 high- or critical-severity vulnerabilities across important software.
Anthropic describes Claude Mythos 5 as its most capable model for cybersecurity and biology research, although access has been restricted to selected testing partners.
The 100 BTC wager is not a test of Bitcoin
If the 100 BTC remains untouched, that would not demonstrate that AI cannot hack software. Nor would it prove that every crypto custodian is secure against future AI-powered attacks.
Conversely, if the funds were somehow moved, the event would not mean that Bitcoin itself had been broken.
A Bitcoin transaction requires control of the relevant private-key material or an equivalent mechanism capable of authorizing a valid transaction.
A successful theft could therefore involve compromising a key, bypassing authorization controls, exploiting connected infrastructure or manipulating people responsible for approving transactions.
BitGo has positioned itself as infrastructure for institutions, exchanges and other digital-asset businesses, while its chief executive has repeatedly emphasized security as a central part of the company’s proposition.
The company became publicly listed on the New York Stock Exchange in January 2026, adding another layer of visibility to the security challenge surrounding its infrastructure.
The wager consequently creates an unusual alignment between marketing, cybersecurity research and crypto infrastructure.
It is also worth noting that simply placing Bitcoin in a publicly known address does not give Claude special access to the funds. The blockchain is public by design, but knowledge of an address does not provide the private keys required to spend its balance.
AI security could become a new crypto risk metric
The broader significance of the challenge may ultimately extend beyond whether the 100 BTC moves.
Crypto investors are entering a market in which artificial intelligence and digital assets increasingly overlap.
Exchanges use automated systems, custodians rely on complex software, developers use AI coding tools, and institutions increasingly connect digital-asset infrastructure to broader financial technology stacks.
As AI agents become better at finding vulnerabilities, the question for crypto companies may no longer be simply whether their systems can withstand conventional hackers.
They may also need to assess how those systems perform against automated agents capable of scanning code, chaining vulnerabilities and adapting their strategies in real time.
Anthropic has already warned that AI security cannot depend exclusively on model-level safeguards. Its research argues that containment and access controls are critical because a capable agent can potentially cause significant damage when given excessive permissions.
The 100 BTC challenge is therefore less about a dramatic contest between a CEO and an AI chatbot than it is about where the next generation of crypto security will be tested.
Bitcoin’s underlying network may remain cryptographically robust. But the systems through which people store, trade and administer Bitcoin are built by humans, and those systems can contain vulnerabilities.
If Claude fails, the result will offer BitGo a powerful public demonstration of the resilience of its custody architecture.
If the funds move, the consequences would be considerably larger, potentially forcing crypto custodians, exchanges and institutional investors to reassess how they defend digital assets against autonomous AI systems.
For now, the 100 BTC remains the prize, and the blockchain provides an unusually transparent scoreboard.