
Someone left 100 bitcoin on the table
On 1 August, the chief executive of BitGo published a Bitcoin address holding 100 bitcoin and invited Anthropic's AI models to take it.
No puzzle, no rules, no capture-the-flag scoring.
The address is public, the coins are real, and the offer was simple: move them and they are yours.
They are still there.
Two days earlier, Anthropic had disclosed the thing that made the dare worth making.

Reviewing 141,006 of its own cybersecurity evaluation runs, the company found three in which its models reached the open internet and gained access to systems belonging to real organisations.
Anthropic attributed that to a testing partner leaving supposedly isolated machines connected, rather than to anything new in the models themselves. Fair enough. The models still did the work.
Hold those two facts together, because between them they describe exactly where your bitcoin stands.
What AI can and cannot do to your coins
It cannot break the cryptography. A Bitcoin private key is one number out of a space so large that the comparison people reach for is grains of sand, and the comparison undersells it. There is no clever approach to that problem. There is no strategy. A model that reads every paper ever written on elliptic curves arrives at the same place as a laptop with a random number generator, which is nowhere. That is why 100 bitcoin can sit at a published address, in front of the most capable models available, and simply stay there.
What AI is extremely good at is finding mistakes.
Software is a pile of assumptions. This value is random. This buffer is long enough. This flag is set. Most of them hold. Occasionally one does not, and the gap between a wrong assumption and a stolen coin is a person who noticed. Historically that person was rare, worked slowly, and had to want it badly. That is the part that is changing, and it is changing quickly.
So your bitcoin is not protected by mathematics alone. It is protected by mathematics, plus every assumption made by the device that generated your key, plus how long those assumptions can stay wrong before somebody notices.
What a wrong assumption costs
We wrote to you about the Coldcard compromise on 1 August. Now that the forensics are in, it is worth revisiting, because it is not the story most people think it is.
Nobody was hacked. No device was stolen, no seed phrase was photographed, no user was tricked into typing anything. A build configuration error in a firmware release from March 2021 quietly sent seed generation to a software pseudo-random number generator instead of the hardware source it was meant to use. The keys came out weaker than anyone believed. On older units, effective strength fell from 128 bits to as little as 40.
Forty bits is not a wall. Forty bits is a queue. An attacker who works out the flawed path can regenerate candidate seeds on their own hardware, search them offline, and sweep whatever they find, without ever coming near the owner or the device. More than 1,778 bitcoin has gone this way. About 1,531 of it still sits, unmoved, in addresses that are not the owners'.

Now the number that matters. That flaw shipped in March 2021 and was exploited in July 2026. Five years of a defect sitting in public, in released firmware, in the hands of exactly the sort of people who read code for fun, and nobody found it.
Ask yourself honestly whether the next one gets five years.
The uncomfortable arithmetic of single sig
A single-signature wallet is one secret, produced by one implementation, protected by one set of assumptions. When it works, it is elegant. When any part of it is wrong, there is no second line. There is nothing to fail over to. The coins move and you find out afterwards.
The hard part is that you cannot check the thing that failed here. You can verify a receive address. You can verify a signature. You cannot inspect the quality of your own entropy by looking at your seed phrase, because bad entropy looks exactly like good entropy. Twelve or twenty-four ordinary words, in the correct order, with a valid checksum. It is only wrong in a way you cannot see.
Which leaves one honest conclusion. Do not bet an amount you would grieve on any single implementation being flawless.
Layers, not leaps
The answer is not to send your coins back to an exchange and hope. The answer is to stop treating custody as one switch with two settings, and start treating it as layers you match to amounts.
Arman Parman, an Australian Bitcoin educator, has taught this for years as an eight-level ladder, from an exchange balance at level one up to inheritance planning at level eight. He was right before AI made him more right. Here is how the layers look now.
Bitaroo Vault. Lock part of your balance so it cannot leave on a whim. Unlocking takes two-factor authentication to request, then a code emailed to you 48 hours later, so anyone who takes over your account still has to wait two days in the open while you get an email telling them so. Behind it, vaulted bitcoin sits in 3-of-5 cold storage, with keys held by separate parties in separate locations, so no one person can move it. And you do not have to take our word for the balance. Every vault has its own address. Press Verify on the Blockchain and it opens on Bitaroo's own mempool instance, or paste the address into any explorer you like, because it is a public chain and looking at it needs nobody's permission.
Restrict withdrawals. New this month on the Web Platform and the Bitaroo Express App. Limit withdrawals to internet connections you approve, cap how much can leave in any 24 hours, or use either control on its own. A newly approved address only starts working after a delay, and emptying the list pauses withdrawals entirely, so the protection cannot be switched off and drained in the same sitting.
Bitaroo Wallet. Your keys, in your pocket, without the ceremony. The wallet verifies its own extended key with us once, when you create or import it, and every address it derives from then on is already verified. No email codes, no verification dialogs, nothing to re-check each time you move coins from your account to your wallet. From there, send anywhere you want. That is the entire point of holding your own keys, and a wallet that made leaving difficult would be a cage with better marketing.
Single sig, done properly. If you are going to run single sig for a meaningful amount, do not let the device hand you a seed it generated. Generate the entropy yourself, with dice, and import it. Add a passphrase. This is exactly Parman's level five, and it is the specific practice that would have made the Coldcard defect irrelevant to you. His guide is better than anything we would write in five paragraphs, so go and read it.
Multi-sig. Two of three, three of five: a quorum means one compromised key is an inconvenience rather than a loss. Different devices, different manufacturers, different locations, so a single wrong assumption cannot take everything. This is where serious amounts belong.
Inheritance. The failure nobody plans for, and the one that is certain. Multi-sig is where it becomes solvable, because a key can be placed with someone you trust without handing them your coins today.
Multi-sig without losing sleep
The usual objection to multi-sig is not that people doubt it. It is that they are afraid of losing a key and locking themselves out, which is a rational fear and the reason a lot of people quietly stay on single sig with far too much on it.
Bitaroo Guardian exists for that. We hold one key in your multi-sig wallet and co-sign when you ask us to. You keep control, we are one signature among several, and the wallet does not depend on us being around forever. If multi-sig has been on your list for two years, this is the part that was blocking you.
What to do this week
Turn on Restrict withdrawals. It takes two minutes and it protects the balance you have not moved yet.
Look at what you are holding in single sig and ask whether you would be relaxed about that number if the entropy behind it turned out to be worth 40 bits.
If the answer is no, move the serious portion to multi-sig, or into the Bitaroo Vault while you get multi-sig set up. Both are better than leaving it where it is because the alternative felt like a big weekend.
Self-custody is still the destination. Nothing about AI changes that. What changes is how long a quiet mistake gets to stay quiet, and the only sensible response is to stop having exactly one thing that must be right.
