Morning Edition · Sunday, August 16, 2026Published at 2:12 AM EDT · New York
Galaxy names Kimi K3 as an example of the kind of open model it believes found and exploited the flaw. One defender told Galaxy that safety policies at United States frontier labs left security researchers with little choice but to rely on the same Chinese open weights the attackers are believed to have used.

Galaxy Research published a report on August 14 saying it assesses with high confidence that at least some of the attackers who emptied Coldcard hardware wallets used artificial intelligence (AI) models running without cybersecurity safeguards. Confirmed losses stand at 1,778.84 bitcoin taken from more than 8,600 addresses, and the firm has recorded no attacker activity since August 6.
The report names the recently released open-source Kimi K3 model as an example of the kind of system it believes was used, both to find the vulnerability and to carry out the theft. Galaxy says it has identified at least 33 additional attacker footprints and believes multiple parties were involved, though it cannot confirm whether the separate attack waves trace back to a single group.
The attribution deserves scrutiny. Galaxy is inferring which tools were used from attack behavior, not from model logs or seized infrastructure, and a firm that runs a custody and trading business has a financial interest in a narrative where self-custody hardware faces attackers operating at machine speed. What is independently documented is the theft itself: The Hacker News tracked roughly $70 million moving in about 41 minutes, and Decrypt reported the running total passing $88 million as the drains continued. Galaxy's earlier count, 1,367 bitcoin, has since risen.
The imbalance the report describes matters more than the attribution itself. Rob Hamilton, chief executive of the bitcoin custody firm Anchorwatch, told Galaxy that safety policies at United States frontier labs largely prevented security researchers from using top closed models to defend against the attacks, leaving defenders reliant on the same Chinese open weights the attackers are believed to have used. Separately, former OpenAI researcher Daniel Kokotajlo said publicly that models already have the capability to hack wallets and bank accounts, a claim that remains an assertion about capability rather than evidence of any specific intrusion.
Part of a tracked trend
Autonomous Agents Move Into Cyber Offense
AI agents increasingly run end-to-end intrusions, chaining supply-chain footholds into privilege escalation and credential theft at machine speed, outpacing human and current automated defenses.
Start a discussion in Townsquare.
More from this edition
Coinkite, whose March 2021 build error collapsed seed entropy from 128 bits to roughly 40 and which gains from attention moving to an outside artificial intelligence (AI) capability, plus Galaxy, a custody and trading business whose commercial position improves when self-custody hardware looks exposed to machine-speed attackers, and the policy camp arguing that United States labs should loosen security restrictions.
The theft is documented independently (TRM Labs counts about $116 million, Bloomberg and TechCrunch tracked the drains in real time), but the AI attribution is inferred from attacker behavior rather than from logs or seized infrastructure, and a 40-bit keyspace is brute-forceable with conventional computing, so no model was strictly required to carry out the attack even if one was used to find the flaw.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The binding constraint on offensive artificial intelligence (AI) use is no longer model quality, it is the absence of refusal behavior, and downloadable open weights supply that for free. Frontier labs that restrict security-relevant capability through usage policy pay a double cost: attackers bypass the restriction by using open weights instead, and defenders lose access to the strongest available tools, which pushes demand for security work toward self-hosted Chinese models. Hardware wallet vendors and custodians are directly exposed through insurance pricing and audit costs, because a vulnerability class that once required a specialist can now be searched for cheaply and at scale.
What to watch
Observations to monitor, not financial advice.
Synthesized from: The Crypto Times · The Hacker News · Decrypt · Crypto Briefing · Polylog editors
Comments
1Aug 17, 1:11 AM · edited
The report's finding that defenders already rely on the same unrestricted open weights as attackers means current US frontier lab safety restrictions have inverted their intended effect for hardware security research.