NewsCryptoWhitehats Move 52.37 BTC From Coldcard Exploit Wallets Into Wyoming Recovery Trust

Whitehats Move 52.37 BTC From Coldcard Exploit Wallets Into Wyoming Recovery Trust

Author: Coinotag·

Key Takeaways

  • •Whitehat operators moved 52.37 BTC from addresses hit by July's Coldcard exploit into a Crypto Recovery Trust address, confirmed in Bitcoin block 967,948 with an OP_RETURN claim message.
  • •Galaxy Digital calculates the sweep represents 2.8% of tracked exploit funds, with roughly 40% of the Wave 2 cluster identified as whitehat activity rather than theft.
  • •The exploit stemmed from a 2021 firmware defect that routed seed generation to a weak software pseudorandom generator, allowing attackers to regenerate private keys offline and drain about 1,789.28 BTC worth $154.1 million.
  • •Coinkite's patches, beginning with emergency fixes on July 31, only correct future seed generation, so owners of wallets created under vulnerable firmware must generate new seeds and migrate their funds.
  • •Additional recoveries include 3.0134 BTC of unconfirmed funds in the same sweep and a separate 40.71 BTC consolidation on Sept. 21 tagged for the trust's claims process.
Whitehats Move 52.37 BTC From Coldcard Exploit Wallets Into Wyoming Recovery Trust

Whitehat operators have moved 52.37 Bitcoin (BTC) out of addresses drained in July's Coldcard hardware-wallet exploit, consolidating the coins into a fresh address tied to a recovery trust established to return them to verified owners, according to on-chain tracking.

Galaxy Digital's head of research, Alex Thorn, laid out the sweep, saying the funds came from the tracked Wave 2 cluster together with footprints labeled AA, AU and AX. The consolidation was confirmed in Bitcoin block 967,948, and the destination transaction carried an OP_RETURN message reading "claim:cryptorecoverytrust dot com." OP_RETURN is a Bitcoin script opcode that lets a transaction carry a short embedded note permanently visible to anyone inspecting the ledger, which is how sweeps of this kind make their intended destination publicly readable on-chain.

Thorn calculated that the 52.37 BTC represents 2.8% of the exploit funds his team is tracking, and that roughly 40% of Wave 2 has now been identified as whitehat activity rather than theft — security researchers who secure vulnerable coins ahead of thieves and route them into custody so the funds can be returned through a claims process instead of kept. An additional 3.0134 BTC with no prior tracking history also reached the trust address in the same transaction, which Thorn flagged as presumably more recovered coins but left unconfirmed.

The destination is the Crypto Recovery Trust, whose legal form is the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC named as trustee. The entity's stated role is to reunite recovered Bitcoin assets with their rightful owners through a formal claims process covering blockchain analysis, proof-of-ownership checks and sanctions screening.

A separate recovery vehicle, the Digital Asset Recovery Trust (DART), had disclosed before this week's consolidation that it and independent whitehats secured just over 50 BTC from vulnerable addresses as of Aug. 17, placing the coins in trust custody rather than researcher-controlled wallets. Funds tied to competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures, and movements of this size would ordinarily be tagged as whale transfers rather than recoveries. Thorn's 2.8% figure refers to Galaxy's tracked total and should not be read as an official Coinkite loss number.

The seed-generation flaw behind the drain

The Coldcard incident began July 30, when attackers started exploiting weakened wallet seeds produced by affected firmware. Coinkite's incident record explains that a firmware integration defect caused the seed-generation path to resolve to MicroPython's Yasmar software pseudorandom generator instead of the intended hardware random number generator.

The attackers did not need to remotely control the devices: once the reduced randomness made affected seed phrases easier to search, they simply regenerated the vulnerable private keys offline. Independent technical research traced the weakness to firmware changes dating from 2021 and estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under the affected conditions, while Mk4, Mk5 and Q models retained about 72 bits — far below the intended security level.

Early losses were modest compared with the totals that emerged later. The first wave stripped roughly 594 BTC from around 500 wallets in approximately 25 minutes, and as analysts expanded the identified scope across four attack waves, tracking grew to about 1,816 BTC moved from more than 5,200 addresses, with estimated losses exceeding $100 million.

Coinkite shipped emergency fixes on July 31 — version 5.6.0 for Mk4/Mk5 and 1.5.0Q for Q devices, alongside patches covering older Mk2/Mk3 hardware — and its current recommended standard releases are 5.6.2 and 1.5.2Q, both issued Sept. 3. The company stresses that the patches correct future seed generation only: a wallet created under vulnerable firmware remains exposed even on a fully updated device, because the weakness lives in the seed itself. Owners of affected seeds are told to generate a corrected replacement and migrate their funds, unless they meet the stated independent-dice exception, under which at least 50 fair, privately recorded six-sided dice rolls add at least 128 bits of entropy; anyone uncertain is told to move.

Every recovery consolidation is now traceable on Bitcoin's proof-of-work ledger, which doubles as the shared evidence layer for the cleanup.

On-chain trail backs the claims process

Further details have since emerged on the recovery effort. Galaxy Digital now places the total exploit loss at 1,789.28 BTC, worth $154.1 million at current prices, with the swept 52.37 BTC valued at more than $4.5 million.

Nick Bax of universal market protocol Ump Labs publicly confirmed his role in the operation, writing on X that at the end of July he helped rescue roughly 50 BTC that were "imminently going to be stolen" due to the entropy flaw, and that the funds are held by a Wyoming trust to ensure return to their rightful owners.

Coinkite acknowledged the bug "silently went unnoticed" and that its potential impact grew with every release. Since the attack, cautious investors have been shifting coins to other storage solutions, including exchanges.

A separate consolidation has also come into view, with Galaxy Research's monitoring showing 40.71 BTC, worth about $3.31 million, moved on Sept. 21 in a single transaction carrying an OP_RETURN note reading "claims: cryptorecoverytrust.com." That transfer spanned 11 addresses across 20 inputs and 480 outputs, with the coins attributed to attackers tagged as "Footprint AA" together with a second-wave hop from the hack.

Galaxy's data also frames the broader picture: the exploit peaked at roughly $130 million, and much of the stolen Bitcoin sat untouched in attacker addresses for weeks before the sweeps, fueling speculation about whether it would ever move at all. The trust-tagged movements indicate that at least some parties are now actively shepherding funds back toward victims rather than leaving the haul dormant. How the rest of the picture resolves is likewise readable on-chain: whether further attacker-tagged footprints surface in future trust-tagged consolidations, whether the unconfirmed 3.0134 BTC is confirmed as recovered, and how many verified owners clear the trust's proof-of-ownership and sanctions checks to reclaim funds.

Verifiable evidence

The episode stands out for its verifiability. The researcher published transaction ID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47, so anyone can independently confirm the sweep in block 967,948, while Coinkite's own security status page states the root cause rather than deflecting. That pairing — primary on-chain evidence plus a formal trust structure with sanctions screening — sets a template for hardware-wallet incident response. For users who hold their own keys, seed generation is now demonstrably part of the attack surface.

(Figures as of 18:31 UTC.)