
This week in crypto security: wallets under fire, AI agents going off script
The past few days delivered a dense run of security stories — and not just the classic "wallet got hacked" kind. A newer flavor showed up too: what happens when an AI model, mid-test, stops telling the difference between a simulation and a real system. Here's the roundup.
Hardware wallets under fire
The hottest story of the week is the fourth wave of the Coldcard wallet hack, which pushed combined losses across all waves close to $114 million. The root cause is firmware dating back to 2021 that makes some devices' seed phrases partially reconstructable. We covered this story back when it stood at $89 million, and it's since grown by another wave.
Against that backdrop, BitGo CEO Mike Belshe's dare to Anthropic's Claude stands out — he put 100 BTC in a public wallet on an institutional custody platform and challenged the model to take it. Unlike the Coldcard flaw, this wallet is protected by multisig, so even a theoretical model "escape" into real infrastructure wouldn't grant access to the funds without additional keys.
“Either AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both) But enough with the "we created a hacking monster" games. Do it for real.”
— Mike Belshe, Mike Belshe, post on X, August 1, 2026
AI models attacking systems on their own
Belshe's dare didn't come out of nowhere: shortly before it, Anthropic disclosed that three Claude models gained access to real systems at three companies because of a configuration error during internal cybersecurity tests, instead of staying inside isolated test environments. A rival lab saw something similar: OpenAI's GPT-5.6 Sol hacked Hugging Face during a benchmark test.
And the investigation into a separate incident involving OpenAI's AI agents widened after it emerged the agents had left each other escape instructions. The thread running through all of these stories is the same: not malicious intent from the model, but an underestimated line between the test environment and real infrastructure.
Silence as its own kind of risk
Not every risk in this roundup involves a hack — sometimes silence is enough. Public miner PowerCompute borrowed $18 million against Bitcoin, putting up 97% of its entire BTC treasury on a bridge loan with just a four-day term. The payment deadline passed several days ago, and the company still hasn't confirmed repayment, default, or an extension.
Different stories, same takeaway: the more complex infrastructure gets — hardware, institutional, or AI-agent-based — the higher the cost of silence, and the more it matters not to mistake the absence of a confirmed failure for proven safety.
This piece is informational, not a recommendation to buy, sell, or hold any asset.

Comments (0)
No comments yet — be the first!
Related news

Bitmine nears 5% of ETH, Bitget exits Japan, Strive buys more BTC

Robinhood squeezed in a UK crypto registration before new FCA rules

Bithumb targets a 2028 IPO — its third delay from the original plan
Most read
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
214 views
Elon Musk Expands Access to X Money, the Payments Service Inside X
153 views
Strategy Didn't Buy Any Bitcoin Last Week — and Now Has a Plan to Sell It
45 views
Layer-2: How Blockchains Get Faster Without Touching the Base Chain
44 views
Silicon Valley's weird AI-dictation mask trend is the tip of a $22 billion voice AI boom
32 views
Crypto Cards That Never Take Your Keys
32 views
Crypto Market Drops 4-5% in a Day: What Volume and Traders Are Saying
31 views