White Hats Move Over $4.5 Million in Bitcoin From Hacked Coldcard Devices to Recovery Trust
Key Takeaways
- •White hats moved 5,237 BTC worth more than $4.5 million from hacked Coldcard devices into Crypto Recovery Trust, a Wyoming trust created to return funds to victims.
- •The security incident stems from a Coinkite firmware bug that caused Coldcard seed generation to fall back to a weak software pseudorandom number generator, letting attackers reproduce users' seed phrases.
- •Thefts tied to the Coldcard exploit began on July 31, and Galaxy Digital estimates 1,789.28 BTC, approximately $154.1 million, was lost in the attacks.
- •Nick Bax of Ump Labs said he helped rescue roughly 50 BTC that were imminently at risk of theft, with the funds now held by the Wyoming trust.
- •Following the attack, cautious investors have been relocating their coins to other storage solutions, including exchanges, while Coinkite urged users to update software or move funds off the devices.

White hats have moved bitcoin out of hacked Coldcard signing devices and into a trust where prospective victims can reclaim it, according to Galaxy Digital's Alex Thorn.
Writing on X on Monday, Thorn said the funds were taken by white hats to protect potential victims and are now sitting in an address controlled by Crypto Recovery Trust, a Wyoming trust created to help white hats return funds to victims. The operation reflects the white-hat rescue model, in which funds exposed to an exploit are moved out of attackers' reach so they can be handed back to their owners.
A total of 5237 bitcoin — worth more than $4.5 million at today's prices — was moved. Thorn added that the sum represented 2.8% of the Coldcard exploit.
The thefts began on July 31, when criminals started draining bitcoin stored with Coinkite's popular Coldcard hardware wallet, a class of device built to keep private keys offline for self-custody. The Canadian manufacturer said a firmware bug caused seed generation on Coldcard devices to fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, effectively allowing hackers to guess users' seed phrases. Because a seed phrase serves as the master backup from which a wallet's private keys are generated, anyone who could reproduce it gained full control of the associated funds.
Galaxy Digital, which tracked the movement of funds, said 1,789.28 bitcoin were lost in the attacks — roughly $154.1 million at today's prices.
Earlier this month, Nick Bax of universal market protocol Ump Labs said he had taken part in the recovery effort.
"Finally able to say that at the end of July, I was involved in the rescue of ~50 BTC which were 'imminently going to be stolen due to the COLDCARD entropy flaw,'" Bax wrote on X.
He added: "The funds are currently held by a Wyoming trust, which will ensure that funds are returned to their rightful owners."
Since the attack, cautious investors have been moving their coins to other storage solutions, including exchanges.
Coinkite said in a statement that the bug "silently went unnoticed" and that "its potential impact grew with every release" of its products. Days after the first hack, the company urged investors to update their software or move their funds off the hardware, as covered in Bitcoin Magazine's earlier report.
This report first appeared on Bitcoin Magazine and was written by Mathew Di Salvo.