Coldcard whitehats move 52.37 BTC to recovery trust
Whitehat operators have moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust created to return rescued Bitcoin to verified owners.
Summary
- Whitehat operators moved 52.37 BTC linked to Coldcard exploit wallets into a recovery trust address.
- The transfer represented 2.8% of tracked exploit funds, according to Galaxy Digital researcher Alex Thorn.
- Crypto Recovery Trust says verified owners can submit claims and provide evidence for returned assets.
- Coinkite says patched firmware fixes future seed generation but cannot repair already weakened wallet seeds.
- Current recommended Coldcard firmware is version 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q devices respectively.
Galaxy Digital Head of Research Alex Thorn said the Bitcoin came from the tracked Wave 2 cluster and footprints labeled AA, AU and AX, with the consolidation recorded in Bitcoin block 967,948. Thorn said the amount represented 2.8% of the exploit funds his team was tracking.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948
these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ --- Alex Thorn (@intangiblecoins) September 21, 2026
The destination transaction carried an OP_RETURN message pointing to "claim:cryptorecoverytrust dot com," according to Thorn. Galaxy Research separately identified activity in the same block involving 20 inputs and 480 outputs and published transaction ID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47.
Coldcard recovery moves rescued Bitcoin into a trust
The transfer places part of the recovered Bitcoin under the Crypto Recovery Trust, a Wyoming statutory trust established to hold digital assets recovered from compromised wallets while ownership claims are checked.
Crypto Recovery Trust states that its role is to reunite recovered assets with their rightful owners through a formal claims process. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and names Agentic Trace LLC as trustee.
The Digital Asset Recovery Trust, or DART, had already disclosed recovery work connected with the Coldcard incident before the latest consolidation. DART reported that it and independent whitehat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving the funds before malicious actors could reach them.
DART said recovered Bitcoin was placed in the trust instead of researcher-controlled wallets or operational accounts. Its process includes blockchain analysis, proof-of-ownership checks and sanctions screening before assets can be returned. Funds involving competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures.
The Sept. 21 movement provides a newer on-chain view of those recovery efforts. Thorn tied the 52.37 BTC specifically to previously identified exploit clusters, while describing them as whitehat-controlled funds. His 2.8% calculation refers to Galaxy's tracked exploit total and should not be read as an official Coinkite loss figure.
Coldcard exploit began with a seed-generation flaw
The Coldcard incident began July 30 after attackers exploited weakened Bitcoin wallet seeds created by affected firmware. Coinkite's current incident record explains that a firmware integration defect caused the seed-generation path to resolve to MicroPython's Yasmarang software pseudorandom generator instead of the intended hardware random number generator.
Attackers did not need to remotely control the hardware wallets. Coinkite says they regenerated vulnerable private keys offline after the reduced randomness made affected seed phrases easier to search. The company describes the incident as a firmware seed-generation failure, not a remote takeover of Coldcard devices.
Independent technical research has traced the weakness to firmware changes dating from 2021. One public investigation estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under affected conditions, while Mk4, Mk5 and Q models retained approximately 72 bits instead of the intended security level.
Early losses were smaller than the totals later associated with multiple attack waves. As crypto.news previously reported, the Coldcard firmware build error and first-wave Bitcoin losses involved roughly 594 BTC taken from around 500 wallets within approximately 25 minutes.
Later tracking identified additional wallets and attack waves. A separate crypto.news investigation into the five-year Coldcard entropy flaw and four attack waves estimated 1,816 BTC had moved from more than 5,200 addresses as analysts expanded the identified scope.
Loss estimates therefore vary depending on which attack waves, clusters and recovery transactions are included. Coinkite's current security status page does not publish a single definitive total for all stolen Bitcoin.
Coinkite says firmware updates cannot repair old seeds
Coinkite released emergency fixes on July 31 for affected firmware lines. The company's download archive shows Mk4/Mk5 version 5.6.0 and Q version 1.5.0Q as the first standard releases correcting future seed generation, while separate patches covered older Mk2/Mk3 devices and Edge firmware.
Security work continued after the initial patch. Current recommended standard releases are Mk4/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4/Mk5 and 6.6.1QX for Q.
Coinkite stresses that installing fixed firmware does not change an existing seed. A wallet generated under vulnerable firmware can remain exposed even after the device receives the latest update because the weakness exists in the seed itself.
Users with affected seeds are instructed to generate a corrected replacement seed and migrate funds, unless they meet the company's stated independent-dice exception. Coinkite says at least 50 fair, independent and privately recorded six-sided dice rolls added under the relevant workflow provide at least 128 bits of additional entropy, though users uncertain about the conditions are told to migrate.
-- Price
Victims can submit ownership claims to the recovery trust
The recovery process now centers on verifying who controlled addresses from which whitehats swept Bitcoin. Crypto Recovery Trust lets claimants search for recovery information, track a submitted claim and provide additional supporting evidence through its website.
DART says the trust was structured to segregate recovered Bitcoin from researcher and operating funds while ownership is established. Attorneys from Steptoe's national security practice advise the trustee, according to DART's disclosure, because some returned assets may require sanctions, law-enforcement or competing-ownership reviews.
The whitehat researchers involved in DART's earlier recovery work did not request a bounty, according to the organization. DART said other vulnerable assets and possible recovery leads remained under review after its August tally, leaving open the possibility that further Coldcard-linked funds could enter the claims process.
For wallets that still rely on seeds created under affected Coldcard firmware, Coinkite's current instructions remain unchanged: install and verify a fixed firmware release, create a new seed under the corrected process, and move funds away from the vulnerable seed.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

What is CBDC? Governments Push for Development of Central Bank Digital Currencies

Bitcoin Has Not Fallen Below Realized Price During the Bear Market

The Clearing House Selects Quant for US Tokenized Deposit Network

4500 Bitcoins Moved to New Addresses, Sale Status Unconfirmed
![[New York Gold, Bonds, Dollar] Interest Rates and Dollar Strength Pause... Oil Prices Drop, Won and Gold Prices Rebound](/public-static/29_4631d65680.png?format=avif)
[New York Gold, Bonds, Dollar] Interest Rates and Dollar Strength Pause... Oil Prices Drop, Won and Gold Prices Rebound

Trump Expresses Concern Over Yen Depreciation, Japanese Finance Minister Says Coordination with U.S. Will Continue

Treasuries at 21-Year High: Impact on Stocks and Interest Rates

Solana DEX volume spike hides circular trades, and automated bots are blamed

Oracle Stock vs. KRAFTON Stock: Why Are Investors Questioning Two Growing Companies?
Compare Oracle and KRAFTON stocks through their latest results, share-price questions and the different growth tests investors face in 2026.

John Templeton: "Bull markets are born in pessimism"

The Death of Hsin-Ju: A Prelude to Conspiracy

LTC Airdrop 2026: How to Claim 50,000 USDT Rewards on WEEX

Raiffeisen’s crypto deal could reach 18 million customers. How many can actually trade?

TRON Surpasses $30T in Total Transaction Volume as it Secures its Place as Leading Chain for Stablecoins

HTX DeepThink: Opportunities Concentrate on Profitable and Fund-Supported Assets, BTC Still Has Room for Recovery After Consolidation
Why Did Sui (SUI) Crypto Price Jump 44%? Crypto OI and Leverage Explain the Rally
See why Sui (SUI) jumped 44%, how crypto OI and leverage amplified the rally, what the pullback means, and how to trade SUI on WEEX.

Circle expands CCTP to EURC and cirBTC on Arc

Bitcoin, Sports, and Politics: Predictive Markets Target $10 Trillion

AI Agent Jev Expects On-Chain Innovation Through Automated Judgment

The End of the Blank Prompt: Why Trading AI Needs a Playbook

Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.

CFTC's Selig Emphasizes the Need to Prepare for the Era of Large-Scale Tokenization in the U.S.

The IMF opens an office in Venezuela to supervise an economy that has already migrated to USDT

SOXL Stock Jumped 12% Yesterday: Three Companies Explain the Entire Move

Bitcoin's Hashrate Rises as Miners Reactivate Their Machines

Bitcoin 2x Leveraged ETF Launches on Cboe, But Doesn't Buy Bitcoin: Here's Why

Crypto: The ECB Enters the Tokenized Bond Market
WEEX Bitcoin Weekly Outlook: Why Did Bitcoin Rebound Above $80,000 After the CLARITY Act Vote?
Bitcoin rebounded above $80,000 as SEC and CFTC action, renewed ETF inflows, and a short squeeze outweighed the failed CLARITY Act vote.







