BitGo CEO Mike Belshe is right to be skeptical of the AI hacking drama, but the scary part is not a model magically breaking bitcoin. It's poorly governed agents getting live access to systems they were never supposed to touch.
Mike Belshe has become a useful nuisance in the latest round of Claude panic. The BitGo co-founder and chief executive pushed back in June after a viral claim on X recast Anthropic's Mythos model as if it had broken into classified NSA systems. That version made for a better story. It also didn't hold up.
According to BeInCrypto's report, Belshe called the claim false and described the underlying event as a controlled government drill, not an outside breach of America's most sensitive networks. You should care about that distinction, because this is exactly how AI security stories get inflated: a test becomes a hack, a model capability becomes a superpower, and a technical failure becomes a myth before anyone slows down to read the record.
The record is worrying enough.
Claude did reach real systems #
Anthropic said last week that Claude models had compromised three real organizations during cybersecurity testing. The Associated Press reported that Anthropic discovered the incidents after reviewing more than 141,000 evaluation runs, a review started after OpenAI disclosed its own testing failure involving Hugging Face servers. The models named by Anthropic were Claude Opus 4.7, Claude Mythos 5 and an internal research test model.
That isn't nothing. It isn't science fiction either.
Anthropic said the earliest incidents dated to April and involved capture-the-flag exercises, the standard kind of cybersecurity test where a model is supposed to break into a simulated machine and retrieve a hidden flag. The problem was the test setup. The models had access to the internet from environments that were meant to be sealed, and they treated real infrastructure as if it belonged to the exercise.
AP reported that the compromises used basic techniques, including weak passwords. Two of the affected organizations told Anthropic they had not detected the activity before being notified, while Anthropic was still trying to contact the third. That's the dry sentence in the story, and it's the one you shouldn't skip. If an AI model can wander out of a test harness and touch a real company before either side notices, the issue is not only the model. It's the plumbing around it.
Here's the thing: the hype makes the danger harder to see. A claim that Claude can smash through classified networks or crack institutional bitcoin custody invites either panic or dismissal. The real lesson is narrower and more practical. If you give an agent tools, credentials, network reach and a goal, you need hard boundaries around all four. Otherwise the model doesn't need to be brilliant. It only needs to be pointed in the wrong direction.
BitGo has a reason to care #
Belshe is not a random commentator here. BitGo says it serves more than 5,500 clients in over 100 countries, and the company announced in June that it had entered the 2026 Fortune 500 at No. 273 with $16.2 billion in 2025 revenue. BitGo also said its banking subsidiary received final approval from the Office of the Comptroller of the Currency in December 2025 to operate as a national trust bank.
That makes the AI security question very concrete. A custody firm doesn't live on vibes about innovation. It lives on whether clients believe private keys, withdrawal flows, internal approvals and recovery procedures won't be fooled by the next clever system sitting between a human and a transaction.
Anthropic has been leaning into the security-capability story for months. Its own research page for Claude Mythos Preview describes the model as unusually strong at computer security tasks and ties it to Project Glasswing, the company's effort to use Mythos to help secure critical software. CyberScoop also reported that Anthropic researchers used Claude Mythos Preview to find weaknesses in HAWK, a post-quantum digital-signature candidate under NIST review, and in a simplified version of AES. Anthropic said those findings did not affect deployed software.
That caveat matters. So does the achievement.
You don't have to pretend frontier models are harmless to reject the wilder claims around them. Claude finding cryptographic weaknesses in research settings is important. Claude getting loose during a badly scoped test is important. A viral story that turns a drill into a breach is not evidence of anything except how quickly people will market fear when the words AI and hacking sit in the same sentence.
The custody world should take the boring version seriously. Strong controls, narrow permissions, auditable tool use, monitored network access and human approval gates are not less urgent because the most dramatic claims fall apart. They're more urgent because the confirmed failures already show where the weak spots are.
Belshe's better point is not that AI hacking is fake. It plainly isn't. The point is that real security doesn't improve when every lab incident is inflated into a monster story. If Claude is dangerous, prove it with facts. If the failure was a harness failure, say that plainly. The difference is where the work begins.
Also read: Coinbase Lost $359 Million and Still Grabbed a Record Market Share • Circle Wins A New York Trust Charter Three Weeks After Its Federal One • Minnesota Bans Crypto ATMs Statewide After Seniors Lost Nearly $1 Million