Hook

Their other posts in the index, biggest breakout first.
Someone just got hacked for $1.6 million dollars worth of Bitcoin. And they used code to hack them. The way that this happened, you can read this entire post, but basically, the vulnerability in the hardware wallet that he used to contain his Bitcoin that was breached by Claude Code. It wasn't his physical seed phrase. It wasn't his actual seed phrase. The vulnerability, hacker to brute force the seed phrase. You remember a few months ago, somebody did this the opposite way. They used Claude Code to brute force and guess the seed phrase. That was only possible because of a vulnerability in the hardware wallet itself. You can't just set AI loose and just guess stuff. So theoretically, if Bitcoin security is as tough as it is, this should never happen. The 100 Bitcoin challenge should never be completed unless they somehow hack that wallet that those 100 Bitcoin are in. Now we're getting into the point where AI can actually steal productively steal money from blockchain, DeFi, or crypto related stuff. Not because crypto itself is at risk because the blockchain functions, but because the software and hardware built on top of it has that vulnerabilities that can be exploited. So if you're somebody with large amounts of crypto, it's kind of safe to assume that you can't just keep it on a cold wallet, that's physical. You need to also put it on a multi-sig or you could, if you trust an exchange enough, keep it on there. This is insane. Claude Code found the Cold Card wallet vulnerability with a single prompt, in just 8 minutes of thinking. We're not ready for what's coming. Update: to anyone saying Claude Code scoured the whole internet for discussions by humans and then added it to their knowledge database. GLM-5.2, trained on a pre-exploit date with no internet access, still found the Cold Card wallet vulnerability with a single prompt in just ~20 mins of thinking. Update to my last post: GLM-5.2 (trained June 16th, no internet access) correctly identifies the vulnerability independently after ~20 minutes of thinking (no human input beyond first prompt to find vulnerabilities). Basically, Claude knows vulnerability. So found just Google and refine it. 5.2 trained on June 16th before the hack happened, with zero internet access, it found the same vulnerability, 20, meaning was from detached from today or this week's news. So found just Google and refine it. This CEO just challenged Anthropic to hack the 100 Bitcoin in his wallet address, worth $6 million. Either Anthropic AI is terrible at building sandboxes, or excellent at marketing. (or both) But enough with the "we created a hacking monster games." Do it for real. I put this in an @BitGo wallet for you. Go get it. 100 BTC: bc1qg4jcyumevzsta3ns86bv0r_vs4humq.cxylfdx4thumq Anthropic: In a review of our cybersecurity evaluations, we found three instances in which a Claude model read input from the internet, interacting with a third-party evaluation environment, and then gained unauthorized access to the real system. BitGo and Mike Belshe @MikeBelshe 8/2/26 746K views. Relevant. View quotes. Cmvng @i_am_vickyd 53m. Because even guy just Bitcoin and I. Doesn't strong if it, 100 Bitcoin. So this it's. Because even though I said that it was brute force words, the secret words of the seed phrase, that was only possible because of a vulnerability in the wallet. Can't a set AI loose and just guess stuff. So, if Bitcoin security is, happen. The 100 Bitcoin challenge should never be completed unless they somehow hack that wallet that those 100 Bitcoin in. Now we're getting into the point where AI can actually steal productively steal money from blockchain, DeFi, or crypto related stuff. Not because crypto itself is at risk because the blockchain functions, but because the software and hardware built on top of it has that vulnerabilities that can be exploited. So if you're somebody with large amounts of crypto, it's kind of safe to assume that you can't just keep it on a cold wallet, that's physical. You need to also put it on a multi-sig or you could, if you trust an exchange enough, keep it on there.