Crypto news report · source clearly identified

White‑Hat Actors Move Coldcard Exploit Funds to Recovery Trust

Galaxy Research says white‑hat actors consolidated coins tied to the Coldcard exploit into a fresh address tagged for a "Crypto Recovery Trust," though the funds represent just 2.8% of the total haul.

White‑hat actors have transferred Bitcoin linked to the Coldcard hardware‑wallet exploit into a newly created address labeled as a "Crypto Recovery Trust." The move, recorded on September 21, consolidates a small portion of the stolen funds and signals an effort to return assets to victims.

Transaction Details

Galaxy Research identified a single transaction moving 40.71 BTC (approximately $3.31 million) across 11 addresses, using 20 inputs and 480 outputs. The transaction includes an OP_RETURN field with the text "claims: cryptorecoverytrust.com." A broader sweep later aggregated 52.37 BTC from multiple attacker clusters into the same trust address, representing roughly 2.8 % of the total exploit proceeds.

Background of the Coldcard Exploit

The exploit originates from a March 2021 firmware flaw in Coinkite’s Coldcard devices that generated seed phrases with insufficient randomness, making private keys guessable. Because the vulnerability was embedded in the seed generation process, firmware updates could not remediate wallets already created on compromised devices.

Scale of the Theft

At its peak, the theft amounted to about $130 million in Bitcoin, spread across thousands of addresses. Most of the stolen coins remained dormant in attacker wallets until the recent white‑hat activity.

Implications and Next Steps

The appearance of a recovery‑trust label suggests an organized attempt to shepherd funds back to affected users. Details on how the Crypto Recovery Trust will operate or how victims can claim their coins have not been disclosed. Coinkite has advised exposed users to generate new seeds and has introduced additional security measures following the breach.

Source & attribution

News Source

Publisher
Decrypt
Original date
September 22, 2026, 7:31 PM
Original headline
White-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'
View original report ↗