Galaxy Research assesses with high confidence that at least some of the attackers who drained Coldcard hardware wallets used AI models without cybersecurity safeguards, according to a report published on August 14.
Confirmed losses have reached 1,778.84 BTC across more than 8,600 addresses, with no attacker activity recorded since August 6.
Defenders Say Safety Policies Left Them Using the Same Models
The report names the recently released open-source Kimi K3 model as an example of the kind of system it believes was used and states the attackers probably relied on such a model to discover the vulnerability as well as to carry out the attack.
Rob Hamilton, chief executive of Anchorwatch, told Galaxy that safety policies at US frontier labs have largely prevented security researchers from using frontier models to defend against the attacks, leaving him and colleagues relying on the same Chinese open-source models as the attackers. Hamilton made the comments on Galaxy’s podcast this week.
Hamilton, Calle of the Cashu open-source project, developer James O’Beirne, and around 25 others have been operating what they call the Bitcoin Red Team, sweeping code repositories across the ecosystem for vulnerabilities and recommending patches, according to the report. O’Beirne separately published the analysis linking the faulty code to Coinkite’s chief technology officer, which The Crypto Times reported on August 9.
The suggestion that AI tooling played a role has been present since the first days of the incident. The Crypto Times reported on July 31 that some observers speculated advanced code-review tools, including AI models, may have helped outsiders identify the flaw before the manufacturer did.
Confirmed Total Rises to 1,778 BTC
Galaxy says it has been in direct contact with 190 victims and puts confirmed losses at 1,778.84 BTC, or $112.7 million, taken from more than 8,600 addresses. Including medium-confidence attacker footprints and a still-unconfirmed fourth wave, the figure would reach 2,417.35 BTC, or $153 million.
That continues a rising tally. Galaxy put confirmed losses at 1,596 BTC on August 4 and 1,719 BTC on August 8, which The Crypto Times covered at the time.
At $112.7 million, the theft ranks twentieth among crypto thefts recorded to date, below Multichain’s $130 million loss in July 2023 and above the $100 million taken from Harmony’s Horizon bridge in June 2022, according to the report.
No Confirmed Activity Since August 6
None of the confirmed high-confidence waves or attacker footprints occurred after August 6, Galaxy says. It attributes the slowdown to vulnerable users having migrated or most funds having already been drained, rather than to any fix.
Beyond the three identified waves, Galaxy says it has found at least 33 additional attacker footprints and assesses with high confidence that multiple attackers were active. It states it cannot confirm whether the waves and footprints are attributable to the same or different attackers.
Galaxy advises anyone still holding funds on a single-signature Coldcard wallet to move them to new addresses. A firmware update does not repair a seed generated on affected firmware, because the seed itself is already compromised.
Most of the Bitcoin Has Not Moved
Of the 1,778 BTC confirmed stolen, 1,531 BTC remains unmoved in attacker-controlled addresses. About 246 BTC has been moved since the thefts, with 65% flowing into Coinjoin mixing transactions and 35% moving onward on-chain, sometimes through peelchains, a technique that splits funds across many small sequential transfers to obscure their path.
A small amount can be traced in part to deposits at exchanges or cross-chain bridges. Galaxy says it has provided lists of attacker addresses to exchanges, compliance and investigative firms, and law enforcement agencies in the hope they can be frozen if the funds reach centralized intermediaries.
No Theft Recorded From a Multisig Wallet
Not one theft transaction took funds from a multisignature wallet, according to the report. Multisignature setups require more than one key to authorize a transaction, so a single compromised seed is not sufficient to move funds.
Casa chief executive Nick Neuman told Galaxy that new customer signups have surged and customers have moved substantial amounts of bitcoin into Casa vaults in the two weeks since the exploit was discovered. Anchorwatch chief operating officer Becca Rubenfeld said her company saw its biggest single week of inflows since inception. Dhruv Bansal, co-founder of Unchained, said framing the incident as a win for custodians and a loss for self-custody misses the point and that the real risk is a single point of failure.
Galaxy Digital operates a digital asset custody business. Its legal disclosure states that affiliates may hold financial interests in assets referenced in its research.
Exchange Balances at Record as Small Transfers Spike
Bitcoin flowing into exchanges exceeded 22,000 BTC in the first four days after the attacks began, and exchange balances stood at 3.683 million BTC as of August 8, an all-time high, according to the report. The count of transfers below 1 BTC into exchanges reached a local high following the incident.
The report also notes BlackRock lowered the minimum for in-kind creation of IBIT ETF shares from native bitcoin to $1 million, from $25 million.
The vulnerability originated in a March 2021 Coinkite firmware update that changed how devices generated randomness during key creation, producing seeds with far less entropy than intended. The Crypto Times maintains an explainer on affected devices and what users should do. Coinkite was contacted for comment at 9:05 am UTC.
Also Read: Bitcoin Options Flash Calm Before $60K-$70K Price Battle
