NewsCryptoWhite-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'

White-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'

Author: Decrypt·

Key Takeaways

  • •White-hat actors moved 52.37 BTC stolen in the Coldcard exploit into a fresh address marked with an OP_RETURN message pointing to cryptorecoverytrust.com.
  • •A single Sept. 21 transaction consolidated 40.71 BTC, worth about $3.31 million, spanning 11 addresses across 20 inputs and 480 outputs.
  • •Galaxy's head of research Alex Thorn said the white-hatted funds represent roughly 2.8 of the total Coldcard exploit, which grew to about $130 million at its peak.
  • •The exploit originated from a March 2021 firmware build error on Coinkite's Coldcard devices that generated seed phrases with too little randomness, leaving private keys guessable and impossible to fix through firmware updates.
  • •The on-chain messages did not detail how the Crypto Recovery Trust will operate or how victims can claim their coins, while Coinkite has urged exposed users to migrate to newly generated seeds.
White-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'

Some of the Bitcoin stolen in the sprawling Coldcard hardware wallet exploit is being moved toward a recovery effort, with white-hat actors transferring funds into what they have labeled a trust intended to return the coins to victims — white hat being the label commonly applied to hackers who recover compromised funds rather than keep them.

According to Galaxy Research's blockchain monitoring, 40.71 BTC, worth about $3.31 million, was moved on Sept. 21 in a single transaction that consolidated coins tied to the exploit. The transfer, spanning 11 addresses across 20 inputs and 480 outputs, carried an OP_RETURN message—a small note embedded in a Bitcoin transaction—reading "claims: cryptorecoverytrust.com." Because such notes are recorded directly on the blockchain, the claim label is publicly visible to anyone inspecting the transaction. Galaxy attributed the coins to attackers it had tagged as "Footprint AA" and to a second-wave hop from the hack.

In a related post, Galaxy's head of research Alex Thorn said a broader sweep pulled 52.37 BTC, drawn from several attacker clusters, into a fresh address flagged for the same Crypto Recovery Trust. He noted that the white-hatted funds represent roughly 2.8% of the total Coldcard exploit—a fraction of the haul that has otherwise remained largely dormant in attacker wallets, leaving the overwhelming majority of stolen coins outside the labeled pool for now.

❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️ 52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948 these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ — Alex Thorn (@intangiblecoins) September 21, 2026

The movement marks a notable turn in one of the year's largest self-custody disasters. The Coldcard exploit stemmed from a March 2021 firmware build error on Coinkite's Coldcard devices that generated seed phrases with far too little randomness, leaving private keys guessable. Because the flaw was baked into how each seed was created, updating the firmware could not fix a wallet that had already been generated on a compromised device — a reminder that in self-custody, a failure at key generation cannot be patched away after the fact.

At its peak, the theft grew to roughly $130 million across thousands of addresses, with Galaxy tracking the sweeps as they unfolded in waves. Much of the stolen Bitcoin had sat untouched in attacker addresses for weeks, prompting speculation about whether any of it would ever move.

The appearance of a recovery-trust label suggests that at least some parties are attempting to shepherd funds back to victims. However, the specifics of how the Crypto Recovery Trust would operate—and how owners might claim their coins—were not detailed in the on-chain messages. Whether further attacker clusters are re-labeled into the trust, and whether claim procedures are published beyond the on-chain notes, are the immediate points for exposed users to watch.

Coinkite has previously urged exposed users to migrate to newly generated seeds and has rolled out new security measures in the wake of the breach.