
Whitehat operators have moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust created to return rescued Bitcoin to verified owners.
Summary
- Whitehat operators moved 52.37 BTC linked to Coldcard exploit wallets into a recovery trust address.
- The transfer represented 2.8% of tracked exploit funds, according to Galaxy Digital researcher Alex Thorn.
- Crypto Recovery Trust says verified owners can submit claims and provide evidence for returned assets.
- Coinkite says patched firmware fixes future seed generation but cannot repair already weakened wallet seeds.
- Current recommended Coldcard firmware is version 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q devices respectively.
Galaxy Digital Head of Research Alex Thorn said the Bitcoin came from the tracked Wave 2 cluster and footprints labeled AA, AU and AX, with the consolidation recorded in Bitcoin block 967,948. Thorn said the amount represented 2.8% of the exploit funds his team was tracking.
The destination transaction carried an OP_RETURN message pointing to “claim:cryptorecoverytrust dot com,” according to Thorn. Galaxy Research separately identified activity in the same block involving 20 inputs and 480 outputs and published transaction ID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47.
Coldcard recovery moves rescued Bitcoin into a trust
The transfer places part of the recovered Bitcoin under the Crypto Recovery Trust, a Wyoming statutory trust established to hold digital assets recovered from compromised wallets while ownership claims are checked.
Crypto Recovery Trust states that its role is to reunite recovered assets with their rightful owners through a formal claims process. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and names Agentic Trace LLC as trustee.
The Digital Asset Recovery Trust, or DART, had already disclosed recovery work connected with the Coldcard incident before the latest consolidation. DART reported that it and independent whitehat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving the funds before malicious actors could reach them.
DART said recovered Bitcoin was placed in the trust instead of researcher-controlled wallets or operational accounts. Its process includes blockchain analysis, proof-of-ownership checks and sanctions screening before assets can be returned. Funds involving competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures.
The Sept. 21 movement provides a newer on-chain view of those recovery efforts. Thorn tied the 52.37 BTC specifically to previously identified exploit clusters, while describing them as whitehat-controlled funds. His 2.8% calculation refers to Galaxy’s tracked exploit total and should not be read as an official Coinkite loss figure.
Coldcard exploit began with a seed-generation flaw
The Coldcard incident began July 30 after attackers exploited weakened Bitcoin wallet seeds created by affected firmware. Coinkite’s current incident record explains that a firmware integration defect caused the seed-generation path to resolve to MicroPython’s Yasmarang software pseudorandom generator instead of the intended hardware random number generator.
Attackers did not need to remotely control the hardware wallets. Coinkite says they regenerated vulnerable private keys offline after the reduced randomness made affected seed phrases easier to search. The company describes the incident as a firmware seed-generation failure, not a remote takeover of Coldcard devices.
Independent technical research has traced the weakness to firmware changes dating from 2021. One public investigation estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under affected conditions, while Mk4, Mk5 and Q models retained approximately 72 bits instead of the intended security level.
Early losses were smaller than the totals later associated with multiple attack waves. As crypto.news previously reported, the Coldcard firmware build error and first-wave Bitcoin losses involved roughly 594 BTC taken from around 500 wallets within approximately 25 minutes.
Later tracking identified additional wallets and attack waves. A separate crypto.news investigation into the five-year Coldcard entropy flaw and four attack waves estimated 1,816 BTC had moved from more than 5,200 addresses as analysts expanded the identified scope.
Loss estimates therefore vary depending on which attack waves, clusters and recovery transactions are included. Coinkite’s current security status page does not publish a single definitive total for all stolen Bitcoin.
Coinkite says firmware updates cannot repair old seeds
Coinkite released emergency fixes on July 31 for affected firmware lines. The company’s download archive shows Mk4/Mk5 version 5.6.0 and Q version 1.5.0Q as the first standard releases correcting future seed generation, while separate patches covered older Mk2/Mk3 devices and Edge firmware.
Security work continued after the initial patch. Current recommended standard releases are Mk4/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4/Mk5 and 6.6.1QX for Q.
Coinkite stresses that installing fixed firmware does not change an existing seed. A wallet generated under vulnerable firmware can remain exposed even after the device receives the latest update because the weakness exists in the seed itself.
Users with affected seeds are instructed to generate a corrected replacement seed and migrate funds, unless they meet the company’s stated independent-dice exception. Coinkite says at least 50 fair, independent and privately recorded six-sided dice rolls added under the relevant workflow provide at least 128 bits of additional entropy, though users uncertain about the conditions are told to migrate.
Victims can submit ownership claims to the recovery trust
The recovery process now centers on verifying who controlled addresses from which whitehats swept Bitcoin. Crypto Recovery Trust lets claimants search for recovery information, track a submitted claim and provide additional supporting evidence through its website.
DART says the trust was structured to segregate recovered Bitcoin from researcher and operating funds while ownership is established. Attorneys from Steptoe’s national security practice advise the trustee, according to DART’s disclosure, because some returned assets may require sanctions, law-enforcement or competing-ownership reviews.
The whitehat researchers involved in DART’s earlier recovery work did not request a bounty, according to the organization. DART said other vulnerable assets and possible recovery leads remained under review after its August tally, leaving open the possibility that further Coldcard-linked funds could enter the claims process.
For wallets that still rely on seeds created under affected Coldcard firmware, Coinkite’s current instructions remain unchanged: install and verify a fixed firmware release, create a new seed under the corrected process, and move funds away from the vulnerable seed.












Leave a Reply