Crypto news report · source clearly identified

Whitehat operators move 52.37 BTC to Crypto Recovery Trust

Whitehat operators moved 52.37 BTC from exploit‑linked Coldcard wallets into a recovery trust that will verify claims from affected owners.

Whitehat researchers transferred 52.37 BTC that originated from wallets compromised in the July Coldcard seed‑generation exploit into an address controlled by the Crypto Recovery Trust. The move represents about 2.8 % of the exploit funds tracked by Galaxy Digital.

Background on the Coldcard exploit

The incident began on July 30 when a firmware defect caused the seed‑generation process to use MicroPython’s Yasmarang pseudorandom generator instead of the hardware RNG. This reduced entropy made seed phrases easier to brute‑force. Affected devices included Mk4, Mk5 and Q models, while older Mk3 units provided even less entropy.

Recovery effort and the trust

The Crypto Recovery Trust, a Wyoming statutory trust, was created to hold rescued Bitcoin while ownership claims are verified. The trust’s legal entity is the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC acting as trustee. Claimants can submit evidence through the trust’s website to prove ownership of the recovered funds.

Details of the recent transfer

  • Amount transferred: 52.37 BTC
  • Transaction appears in Bitcoin block 967,948 and includes an OP_RETURN tag referencing “claim:cryptorecoverytrust.com”.
  • Galaxy Digital researcher Alex Thorn linked the funds to the “Wave 2” cluster (footprints AA, AU, AX) and noted the transfer accounts for 2.8 % of the exploit funds his team monitors.
  • The transaction involved 20 inputs and 480 outputs (TXID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47).

Ongoing recovery process

Recovered Bitcoin is held separately from researcher‑controlled wallets. The trust conducts blockchain analysis, proof‑of‑ownership checks, and sanctions screening before returning assets. Claims that involve sanctions, criminal investigations, or competing ownership may follow separate legal procedures.

Current Coldcard firmware guidance

Coinkite recommends installing the latest firmware releases—version 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q devices (released September 3). Updating the firmware does not retroactively secure seeds generated under the vulnerable code; users must create new seeds and migrate funds.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 22, 2026, 7:52 AM
Original headline
Coldcard whitehats move 52.37 BTC to recovery trust
View original report ↗