📈 Get daily crypto insights that make you smarter about your money

Coldcard whitehats move 52.37 BTC into recovery trust as claims process opens

Coldcard whitehats move 52.37 BTC into recovery trust as claims process opens

Whitehat operators have moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust created to return rescued Bitcoin to verified owners, marking a concrete step in one of the largest self-custody security incidents in Bitcoin history.

Galaxy Digital Head of Research Alex Thorn said the Bitcoin came from the tracked Wave 2 cluster and footprints labeled AA, AU and AX, with the consolidation recorded in Bitcoin block 967,948. The amount represented 2.8% of the exploit funds his team was tracking.

The destination transaction carried an OP_RETURN message pointing to a claim address at the Crypto Recovery Trust, according to Thorn. Galaxy Research separately identified activity in the same block involving 20 inputs and 480 outputs and published the transaction ID on-chain for public verification.

How the recovery trust works

The transfer places part of the recovered Bitcoin under the Crypto Recovery Trust, a Wyoming statutory trust established to hold digital assets recovered from compromised wallets while ownership claims are checked.

The trust’s role is to reunite recovered assets with their rightful owners through a formal claims process. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and names Agentic Trace LLC as trustee.

The Digital Asset Recovery Trust, or DART, had already disclosed recovery work connected with the Coldcard incident before the latest consolidation. DART reported that it and independent whitehat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving the funds before malicious actors could reach them.

DART said recovered Bitcoin was placed in the trust instead of researcher-controlled wallets or operational accounts. Its process includes blockchain analysis, proof-of-ownership checks and sanctions screening before assets can be returned. Funds involving competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures.

The Sept. 21 movement provides a newer on-chain view of those recovery efforts. Thorn tied the 52.37 BTC specifically to previously identified exploit clusters while describing them as whitehat-controlled funds. His 2.8% calculation refers to Galaxy’s tracked exploit total and should not be read as an official Coinkite loss figure.

The exploit began with a seed-generation flaw

The Coldcard incident began July 30 after attackers exploited weakened Bitcoin wallet seeds created by affected firmware. Coinkite’s current incident record explains that a firmware integration defect caused the seed-generation path to resolve to MicroPython’s Yasmarang software pseudorandom generator instead of the intended hardware random number generator.

Attackers did not need to remotely control the hardware wallets. Coinkite says they regenerated vulnerable private keys offline after the reduced randomness made affected seed phrases easier to search. The company describes the incident as a firmware seed-generation failure, not a remote takeover of Coldcard devices.

Independent technical research has traced the weakness to firmware changes dating from 2021. One public investigation estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under affected conditions, while Mk4, Mk5 and Q models retained approximately 72 bits instead of the intended security level.

Early losses were smaller than the totals later associated with multiple attack waves. The initial firmware build error and first-wave losses involved roughly 594 BTC taken from around 500 wallets within approximately 25 minutes.

Later tracking identified additional wallets and attack waves. A separate investigation into the five-year entropy flaw and four attack waves estimated that 1,816 BTC had moved from more than 5,200 addresses as analysts expanded the identified scope.

Loss estimates therefore vary depending on which attack waves, clusters and recovery transactions are included. Coinkite’s current security status page does not publish a single definitive total for all stolen Bitcoin.

Firmware updates cannot repair old seeds

Coinkite released emergency fixes on July 31 for affected firmware lines. The first standard releases correcting future seed generation were Mk4/Mk5 version 5.6.0 and Q version 1.5.0Q, while separate patches covered older Mk2/Mk3 devices and Edge firmware.

Security work continued after the initial patch. Current recommended standard releases are Mk4/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4/Mk5 and 6.6.1QX for Q devices.

Coinkite stresses that installing fixed firmware does not change an existing seed. A wallet generated under vulnerable firmware can remain exposed even after the device receives the latest update because the weakness exists in the seed itself.

Users with affected seeds are instructed to generate a corrected replacement seed and migrate funds, unless they meet the company’s stated independent-dice exception. Coinkite says at least 50 fair, independent and privately recorded six-sided dice rolls added under the relevant workflow provide at least 128 bits of additional entropy, though users uncertain about the conditions are told to migrate regardless.

What victims should do now

The recovery process centers on verifying who controlled the addresses from which whitehats swept Bitcoin. The Crypto Recovery Trust lets claimants search for recovery information, track a submitted claim and provide additional supporting evidence through its website.

DART says the trust was structured to segregate recovered Bitcoin from researcher and operating funds while ownership is established. Attorneys from Steptoe’s national security practice advise the trustee, because some returned assets may require sanctions, law-enforcement or competing-ownership reviews.

The whitehat researchers involved in DART’s earlier recovery work did not request a bounty, according to the organization. DART said other vulnerable assets and possible recovery leads remain under review, leaving open the possibility that further Coldcard-linked funds could enter the claims process.

For wallets that still rely on seeds created under affected Coldcard firmware, the company’s instructions remain unchanged: install and verify a fixed firmware release, create a new seed under the corrected process, and move funds away from the vulnerable seed.

As of the latest market snapshot, Bitcoin trades at 86,238 USD, Ethereum at 2,750.10 USD and Solana at 117.93 USD.

10 thoughts on “Coldcard whitehats move 52.37 BTC into recovery trust as claims process opens”

  1. 52.37 BTC consolidated in block 967,948 with an OP_RETURN pointing to the claims address. Thorn’s team publishing the txid for public verification is the kind of transparency this whole mess needed.

    1. 2.8% of tracked funds sounds small until you remember galaxy was watching multiple clusters. the wave 2 stuff moving means the whitehats got there before drainers did

  2. the seed path resolving to Yasmarang, a software PRNG, instead of the hardware RNG is nightmare fuel. keys regenerated offline, no device access needed. paranoia about hardware wallets is justified

  3. At least the trust does proof-of-ownership checks and sanctions screening before payouts. Agentic Trace as trustee with a Wyoming statutory structure beats funds sitting in some researcher’s drawer.

  4. 52.37 BTC is only 2.8% of what Thorn is tracking and people are already calling this a win. long way to go before this counts as a rescue

    1. the OP_RETURN pointing to the claim address is such a bitcoin-native way to do this. block 967948, 20 inputs 480 outputs, all public. love it

      1. 20 inputs and 480 outputs in one block is the tell imo, someone sweeping carefully instead of panicking. hope the claims portal can handle 480 people at once lol

        1. the portal backlog is the part nobody is pricing in. 480 outputs on-chain is fine, but proof-of-ownership checks per claimant plus sanctions screening? that queue is gonna outlive the bear market lol

    2. Fair point on 2.8%, but it means the whitehats actually control the Wave 2 keys. Drainers can not undo that part. Every consolidation from here is just catch-up speed.

  5. A Wyoming statutory trust holding recovered coins while claims get verified is honestly a smart structure. Better than some multisig nobody can audit.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$86,166.00-0.4%ETH$2,753.72-0.6%SOL$118.46-0.1%BNB$788.24-1.3%XRP$1.57+2.8%ADA$0.2544+4.1%DOGE$0.1003+1.2%DOT$1.22+1.1%AVAX$11.26+0.3%LINK$13.04-0.4%UNI$10.24+14.4%ATOM$1.84+1.9%LTC$62.94+1.7%ARB$0.2349+4.0%NEAR$4.40+2.9%FIL$1.04+5.9%SUI$1.02-1.3%BTC$86,166.00-0.4%ETH$2,753.72-0.6%SOL$118.46-0.1%BNB$788.24-1.3%XRP$1.57+2.8%ADA$0.2544+4.1%DOGE$0.1003+1.2%DOT$1.22+1.1%AVAX$11.26+0.3%LINK$13.04-0.4%UNI$10.24+14.4%ATOM$1.84+1.9%LTC$62.94+1.7%ARB$0.2349+4.0%NEAR$4.40+2.9%FIL$1.04+5.9%SUI$1.02-1.3%
Scroll to Top