BitGo CEO Dared Claude Fable to Hack His Wallet. Here’s What Actually Happened
Photo by Bermix Studio on Unsplash
Mike Belshe, CEO of BitGo, posted a public challenge daring Anthropic’s new Fable or Opus models to break into his cold wallet holding 100 BTC.
the tweet

Now,

If an AI model actually pulled it off, that’s roughly the kind of headline that moves markets.

Like If Anthropic could actually pull this off, the story would tank crypto within the hour.

But, what is this?

this is an ad.

The top folks have called it immediately.

Belshe runs a bitcoin custody company.

A public dare aimed at Anthropic’s models is free distribution disguised as a security flex.

Someone from Y-Combinator had this perfect comment on it:

the tweet itself is marketing for BitGo’s wallet product.

That’s the tell.

If something is genuinely possible and genuinely dangerous, you don’t dare a lab to try it in public.

You quietly disclose it or you quietly exploit it.

A public challenge only makes sense when the challenger already knows the odds are near zero.

Now, let’s understand.

Why brute forcing Bitcoin isn’t a language model problem.

A few people in the community who clearly work in security or crypto have laid out why this isn’t remotely in reach for any LLM, current or near future.

Umm, but why…

Bitcoin private keys sit behind elliptic curve cryptography.

Cracking that through brute force isn’t a “smarter model” problem, it’s a “you’d need computation that doesn’t exist yet” problem.

Nobody breaks the blockchain itself, they break the storage container around it.

Phishing, malware on a device, a leaked seed phrase, a compromised exchange account.

The wallet holds.

The human next to the wallet doesn’t.

This is the same distinction I keep having to explain to non-technical friends who ask me if ChatGPT can “hack into” something.
The model isn’t the vulnerability.
The person’s password hygiene is.
Photo by Ethan Rougon on Unsplash

A little more…

I read a comment on Reddit that noted the attackers reportedly use a logged-in API account to query the blockchain, which is such a rookie opsec mistake that it undercuts the entire “sophisticated AI hack” narrative on its own.

I think this is the real lesson buried under the viral screenshot.

AI-assisted attacks are happening, just not in the sci-fi way people picture.

It’s not a model discovering a zero day in elliptic curve math.

It’s a model helping someone write exploit code faster, or helping someone phish more convincingly, while the actual vulnerability is still a human being sloppy with keys, sessions, or code reviews.

Faster tooling on top of the same old mistakes.

What this tells builders…

I build small products for a living, not security infrastructure, but this thread is a decent gut check for anyone shipping anything that touches money or user data.

A few things I took away and might immediately apply to my own stack:

  • First, the “AI did it” framing gets used constantly to make ordinary negligence sound like an unstoppable new threat.

It’s a convenient story for whoever got hacked, because it’s scarier and less embarrassing than “we left an API key logged in” or “our entropy generation had a bug.”

Whenever I see a breach post-mortem lean hard on the AI angle, I now read it as a signal to go look for the boring root cause instead.

  • Second, the actual risk to anything I build isn’t a model brute forcing my database.

It’s session tokens, leaked env variables, and reused passwords across services. Funny, I went back through my own Dodopayments and Neon setup after reading this thread just to double check nothing was sitting in a repo it shouldn’t be.

  • Third, marketing dressed as a technical challenge works because it’s genuinely hard to tell the difference between real red-teaming and a PR stunt from the outside.

If you’re evaluating any vendor’s security claims, including your own AI tooling, ask what the actual attack surface is instead of what the headline implies.

On X, Reddit or communities, someone was betting that if Claude actually engaged with this challenge at all.

Belshe’s 100 BTC is safe.

Not because Claude respectfully declined a supervillain arc, but because the premise was never really live in the first place.

The interesting story isn’t whether an AI can crack Bitcoin, it’s how easily a well timed dare can make a hundred thousand people believe, for a few hours, that it might.

In case we are meeting for the first time, come over here, it’ll be worth the roller coaster of articles that are gonna come up in the next few weeks.

Did you get a chance to drop in, to see my bucket?