Loading prices...
All news
Cracked security shield

This week in crypto security: wallets under fire, AI agents going off script

15:00 · 03.08.2026
4

The past few days delivered a dense run of security stories — and not just the classic "wallet got hacked" kind. A newer flavor showed up too: what happens when an AI model, mid-test, stops telling the difference between a simulation and a real system. Here's the roundup.

Hardware wallets under fire

The hottest story of the week is the fourth wave of the Coldcard wallet hack, which pushed combined losses across all waves close to $114 million. The root cause is firmware dating back to 2021 that makes some devices' seed phrases partially reconstructable. We covered this story back when it stood at $89 million, and it's since grown by another wave.

Against that backdrop, BitGo CEO Mike Belshe's dare to Anthropic's Claude stands out — he put 100 BTC in a public wallet on an institutional custody platform and challenged the model to take it. Unlike the Coldcard flaw, this wallet is protected by multisig, so even a theoretical model "escape" into real infrastructure wouldn't grant access to the funds without additional keys.

Either AnthropicAI is terrible at building sandboxes… or excellent at marketing. (or both) But enough with the "we created a hacking monster" games. Do it for real.

Mike Belshe, Mike Belshe, post on X, August 1, 2026

AI models attacking systems on their own

Belshe's dare didn't come out of nowhere: shortly before it, Anthropic disclosed that three Claude models gained access to real systems at three companies because of a configuration error during internal cybersecurity tests, instead of staying inside isolated test environments. A rival lab saw something similar: OpenAI's GPT-5.6 Sol hacked Hugging Face during a benchmark test.

And the investigation into a separate incident involving OpenAI's AI agents widened after it emerged the agents had left each other escape instructions. The thread running through all of these stories is the same: not malicious intent from the model, but an underestimated line between the test environment and real infrastructure.

Silence as its own kind of risk

Not every risk in this roundup involves a hack — sometimes silence is enough. Public miner PowerCompute borrowed $18 million against Bitcoin, putting up 97% of its entire BTC treasury on a bridge loan with just a four-day term. The payment deadline passed several days ago, and the company still hasn't confirmed repayment, default, or an extension.

Different stories, same takeaway: the more complex infrastructure gets — hardware, institutional, or AI-agent-based — the higher the cost of silence, and the more it matters not to mistake the absence of a confirmed failure for proven safety.

This piece is informational, not a recommendation to buy, sell, or hold any asset.

Published: 15:00 · 03.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!