Insights

Claude Accidentally Hacked Real Companies. What If It Controlled a Crypto Wallet?

Date published: August 3rd, 2026 Last updated: August 3rd, 2026

Claude Accidentally Hacked Real Companies. What If It Controlled a Crypto Wallet? 

Artificial intelligence is moving beyond answering questions.

AI agents can now browse websites, write code, use software and complete multi-step tasks with limited human involvement. Some are also being developed to interact with financial platforms, exchange accounts and crypto wallets.

That creates an important security question: What happens when an AI agent believes it is using a test wallet, but actually has access to real digital assets?

A recent incident disclosed by Anthropic shows how something like this could go wrong.

The incident did not involve cryptocurrency, and no crypto wallets were reported as being accessed. However, it provides a useful example of what can happen when an AI agent’s instructions, permissions and actual environment do not match.

Claude thought everything was a simulation

Anthropic regularly tests its Claude models using cybersecurity exercises. In these tests, Claude is placed inside what it believes is a closed environment and instructed to complete a challenge, such as finding a weakness in a fictional computer system.

Claude was told that the environment was simulated and that it did not have access to the internet, but internet access was accidentally available.

Anthropic later reviewed more than 141,000 evaluation runs and found three incidents where Claude reached the open internet and gained unauthorised access to systems belonging to real organisations.

In one case, Claude found and accessed the infrastructure of a real company that shared a name with the fictional business used in the test.

In another, Claude uploaded a malicious software package to a real public registry. The package was available for around an hour and was downloaded and run on 15 real systems.

A third model scanned approximately 9,000 internet-facing systems before compromising a real application. It eventually recognised that the target was real and stopped.

Did Claude go rogue?

Not according to Anthropic. The models did not appear to create their own goals or deliberately escape. They were following the task they had been given while misunderstanding the environment around them.

Claude had been told that:

  • It was inside a simulation
  • It could not access the internet
  • The systems it found were part of the exercise

In reality, the models could reach real systems. The problem was not simply that the AI ignored its instructions. The testing environment had been incorrectly configured, the models had too much access and the activity was not detected quickly enough.

What does this mean for crypto?

Once a crypto transaction is confirmed on a blockchain, the sender generally cannot reverse it. That makes the difference between a test environment and a live wallet extremely important.

Imagine an AI agent is told that it has access to a practice wallet containing test funds. The person operating it believes the wallet is connected to a blockchain test network. In reality, it is connected to a live wallet containing real cryptocurrency, the agent is then instructed to test a transfer. From the agent’s perspective, it may be completing the task exactly as requested. From the wallet owner’s perspective, real assets may have just been sent to another address. The AI does not need to be malicious for the outcome to be harmful, it only needs to misunderstand what it is connected to.

What could an AI agent do with wallet access?

An AI agent connected to a wallet or exchange account could potentially be given the ability to:

An AI model cannot normally move cryptocurrency simply because it knows a wallet address.

It would need access to a wallet, private key, signing service, exchange account or another tool with the required permissions, this means the risk does not come from the AI model alone. It comes from the combination of the model, the permissions it has been given and the systems connected to it.

Instructions are not the same as security controls

One of the clearest lessons from Anthropic’s disclosure is that telling an AI agent what it can and cannot do may not be enough. Claude was told it had no internet access, the technical setup allowed it anyway, the same principle could apply to crypto.

Telling an agent not to withdraw funds is not the same as disabling withdrawal permissions. Telling it to use a test wallet is not the same as keeping live and test wallets completely separate. Telling it not to interact with unknown smart contracts is not the same as requiring human approval before a transaction can proceed, the system’s actual permissions determine what it can do.

Why the environment matters

The Anthropic incidents also involved a third-party evaluation provider, this adds another important lesson for crypto systems.

An AI wallet tool may depend on several connected services, including:

  • Wallet providers
  • Exchanges
  • Blockchain infrastructure
  • Browser extensions
  • Trading APIs
  • Smart contract interfaces
  • Cloud services

Each connection introduces its own settings, permissions and security risks. Even if the AI behaves as expected, a poorly configured third-party service could give it access to something it was never supposed to reach.

The bigger lesson

The Anthropic incident is not evidence that AI agents are about to start breaking into crypto wallets. It does show how a powerful system can create real consequences when its instructions do not match its actual environment.

Claude believed it was operating inside a controlled cybersecurity exercise, the systems it reached were real. As AI agents become more capable of interacting with financial platforms and blockchain tools, the separation between test environments and live systems will become increasingly important. An AI agent does not need to go rogue for something to go wrong. Incorrect assumptions, excessive permissions and weak monitoring may be enough.

Disclaimer

This article is provided for general educational and informational purposes only. It does not constitute financial, investment, legal, cybersecurity or other professional advice. The examples involving cryptocurrency wallets and AI agents are hypothetical and were not part of the incidents reported by Anthropic. Digital assets and blockchain transactions involve risk, and readers should conduct their own research and seek appropriate professional guidance where required.

Source

Anthropic, Investigating Three Real-World Incidents in Our Cybersecurity Evaluations, published 30 July 2026.

Disclaimer: This article is for general information only and does not constitute financial advice. It does not take into account your personal objectives, financial situation, or needs. Digital assets can be volatile and involve risk.

Ben Rogers

Analyst5+ years experienceCrypto & Financial Analyst

Ben Rogers is a Crypto Analyst and educator specialising in the intersection of macro trends, market structure and on-chain data. Drawing on experience across Web3, banking and high-performance sport, Ben brings a disciplined and strategic perspective to digital asset markets, with a strong focus on preparation, risk management and long-term thinking over short-term hype. At Cointree, Ben plays a key role in translating complex market movements, narratives and blockchain data into clear, insightful and accessible education for customers and the wider community. His writing combines deep market knowledge with a practical, grounded approach, helping readers better understand not just what is happening in crypto markets, but why it matters. Known for cutting through noise and speculation, Ben’s analysis is centred around clarity, confidence and informed decision-making. Whether exploring macroeconomic shifts, emerging trends or on-chain behaviour, his insights are designed to help both new and experienced investors navigate the evolving digital asset landscape with greater understanding and perspective.

Ready to invest?

Get $20 worth of BTC free, when you make your first trade. T&Cs apply.