On August 1, Mike Belshe publicly disputed Anthropic’s account of its own AI. The BitGo co-founder and CEO called the company and attached a specific address holding 100 BTC. On-chain records show the balance as untouched: one deposit, one output, nothing spent. The wallet’s reported $6.3 million value reflects the market price of 100 BTC at the time.
Either @AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both)
But enough with the “we created a hacking monster” games.
Do it for real.
I put this in an @BitGo wallet for you. Go get it.
100 BTC:… https://t.co/RhvivRk9YK
— Mike Belshe (@mikebelshe) August 1, 2026
What Anthropic Actually Claimed
Belshe’s challenge followed Anthropic’s disclosure about incidents during its cybersecurity evaluations. At 4:32 AM on July 31, Anthropic published its own account of a review of its cybersecurity evaluations: three incidents in which
“a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different…
— Anthropic (@AnthropicAI) July 30, 2026
The review covered 141,006 transcripts, was prompted by a similar OpenAI disclosure days earlier, and traced the access to a misconfiguration with evaluation partner Irregular. Anthropic said it was not deliberate model behavior. The three models involved (Opus 4.7, Mythos 5, an unreleased research model) reportedly behaved differently once the systems may have looked real: one continued, one concluded it was still in a simulation, one stopped. This account reflects Anthropic’s own characterization of its models’ behavior. Mythos previously played a research-preview role in Anthropic’s Project Glasswing cybersecurity initiative.
This Is the Second Time Belshe Has Put a Number on This Argument
Track the pattern, not just the instance:
| When | What Belshe disputed | His response |
|---|---|---|
| June 2026 | A viral claim, traced to Senator Mark Warner relaying an NSA official’s account, that Anthropic’s Mythos model breached nearly all of the agency’s classified systems | Called it false, on the record, arguing an authorized red-team exercise had been recast as a live compromise |
| August 1, 2026 | Anthropic’s own account of three Claude models gaining unauthorized access during cybersecurity evaluations | Called it sandbox failure or marketing, funded a public 100 BTC wallet as a direct test |
This time, the disagreement is not a statement to evaluate. It is an address anyone can check.
A Moved Wallet Would Settle This. An Untouched One Won’t.
A moved balance would settle the underlying capability question: a production custody wallet drained in public, not a misconfigured test environment. An untouched balance settles nothing on its own. It is consistent both with the capability gap Belshe is arguing for and with Claude simply never being pointed at this specific address. Anthropic has not responded to the challenge, and the wallet remains unspent, according to on-chain records. Anthropic has not said whether it intends to respond to the dare or considers it outside the scope of a legitimate security test. The wallet dare also lands as Anthropic fights a separate legal battle over a Pentagon-imposed supply chain risk label.
AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.
We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.















