# Galaxy Research Ties Coldcard Wallet Drain of 1,778 Bitcoin to Attackers Using an Unrestricted Open-Weight Model

Galaxy names Kimi K3 as an example of the kind of open model it believes found and exploited the flaw. One defender told Galaxy that safety policies at United States frontier labs left security researchers with little choice but to rely on the same Chinese open weights the attackers are believed to have used.

- Published: 2026-08-16T06:12:17.236Z
- Canonical: https://polylog.news/ai/2026-08-16/galaxy-research-ties-coldcard-wallet-drain-of-1-778-bitcoin
- Publisher: Polylog (AI desk)
- Section: crypto
- Sources: [The Crypto Times](https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/), [The Hacker News](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html), [Decrypt](https://decrypt.co/374817/coldcard-bitcoin-exploit-88-million-attackers-draining-wallets), [Crypto Briefing](https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/), [Polylog editors](https://polylog.news)

Galaxy Research published a report on August 14 saying it assesses with high confidence that at least some of the attackers who emptied Coldcard hardware wallets [used artificial intelligence (AI) models running without cybersecurity safeguards](https://www.cryptotimes.io/2026/08/15/coldcard-attackers-likely-used-unrestricted-ai-models-galaxy-says/). Confirmed losses stand at 1,778.84 bitcoin taken from more than 8,600 addresses, and the firm has recorded no attacker activity since August 6.

The report names the recently released open-source Kimi K3 model as an example of the kind of system it believes was used, both to find the vulnerability and to carry out the theft. Galaxy says it has identified at least 33 additional attacker footprints and believes multiple parties were involved, though it cannot confirm whether the separate attack waves trace back to a single group.

The attribution deserves scrutiny. Galaxy is inferring which tools were used from attack behavior, not from model logs or seized infrastructure, and a firm that runs a custody and trading business has a financial interest in a narrative where self-custody hardware faces attackers operating at machine speed. What is independently documented is the theft itself: [The Hacker News tracked roughly $70 million moving in about 41 minutes](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html), and [Decrypt reported the running total passing $88 million](https://decrypt.co/374817/coldcard-bitcoin-exploit-88-million-attackers-draining-wallets) as the drains continued. Galaxy's earlier count, [1,367 bitcoin](https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/), has since risen.

The imbalance the report describes matters more than the attribution itself. Rob Hamilton, chief executive of the bitcoin custody firm Anchorwatch, told Galaxy that safety policies at United States frontier labs largely prevented security researchers from using top closed models to defend against the attacks, leaving defenders reliant on the same Chinese open weights the attackers are believed to have used. Separately, former OpenAI researcher Daniel Kokotajlo said publicly that models [already have the capability to hack wallets and bank accounts](https://t.me/aipost/7852), a claim that remains an assertion about capability rather than evidence of any specific intrusion.

## What this means

The binding constraint on offensive artificial intelligence (AI) use is no longer model quality, it is the absence of refusal behavior, and downloadable open weights supply that for free. Frontier labs that restrict security-relevant capability through usage policy pay a double cost: attackers bypass the restriction by using open weights instead, and defenders lose access to the strongest available tools, which pushes demand for security work toward self-hosted Chinese models. Hardware wallet vendors and custodians are directly exposed through insurance pricing and audit costs, because a vulnerability class that once required a specialist can now be searched for cheaply and at scale.

## What to watch

- Whether any lab relaxes its policy for verified security researchers, which would show that the cost of refusal training to defenders is now being factored into lab decisions.
- Whether investigators produce direct evidence of model use, such as attacker infrastructure or prompts, rather than conclusions inferred from attack patterns.
- Whether cryptocurrency insurers and custodians reprice hardware wallet risk after this incident, which would turn a claim about AI capability into a measurable cost.
