Hands holding a smartphone displaying the Coldcard logo
TECHNOLOGY

Coldcard Whitehats Move 52.37 BTC to Recovery Trust

Image Credit: Shutterstock

Whitehat operators have moved 52.37 BTC linked to the Coldcard hardware wallet exploit into an address associated with the Crypto Recovery Trust, creating a route for affected users to seek the return of funds secured before attackers could take them.

Galaxy Head of Firmwide Research Alex Thorn traced the consolidation to Bitcoin block 967,948. The transaction included an OP_RETURN message directing users to the recovery trust, which was established to hold rescued digital assets while ownership claims are verified.

52.37 BTC Represents 2.8% of Tracked Exploit Funds 

Thorn said the 52.37 BTC came from coins Galaxy had classified under Coldcard attack Wave 2 and three additional footprints labeled AA, AU and AX. He said the amount represents about 2.8% of funds tied to the exploit and that roughly 40% of Wave 2 is now identified as whitehat activity rather than malicious theft.

Another 3.0134 BTC without a previous tracking history entered the recovery address in the same transaction. Thorn said those coins may also be rescued Coldcard funds, but their origin has not been confirmed.

Coldcard Flaw Weakened Wallet Seed Generation 

The Coldcard attacks began July 30 after a firmware flaw weakened how affected devices generated wallet seeds.

Galaxy said faulty firmware could fall back to insufficient software-generated entropy instead of the intended hardware random-number source, allowing attackers to reconstruct some private keys offline and sweep exposed Bitcoin addresses. Galaxy had confirmed at least 1,778.84 BTC worth $112.7 million stolen by Aug. 14.

Coinkite has released fixed firmware, but updating does not repair a seed generated under affected firmware. Users must migrate funds to a newly generated secure seed unless they meet specific remediation exceptions.

Crypto Recovery Trust Will Verify Ownership Claims Before Returning Funds

DART and independent whitehat researchers previously said they had secured more than 50 BTC from vulnerable Coldcard addresses before malicious actors could steal the funds.

The Bitcoin was transferred to the Wyoming-based Crypto Recovery Trust, which conducts blockchain analysis, ownership verification and sanctions screening before assets can be returned to verified owners.

Affected users can check the trust for information about claims linked to their addresses. The 52.37 BTC represents only a small portion of the Bitcoin traced to the Coldcard incident, leaving most stolen funds outside the recovery process.

More For You

Explore More News