White-Hat Hackers Move Stolen Bitcoin Toward Recovery Trust
What happened
Some Bitcoin stolen in a large-scale Coldcard hardware wallet exploit is now being moved toward a recovery effort. White-hat actors transferred coins into an address labeled as a "Crypto Recovery Trust" for victims.
On Sept. 21, a single transaction moved 40.71 BTC, worth about $3.31 million. The transaction consolidated coins from 11 addresses across 20 inputs and 480 outputs. It carried a small embedded message, called an OP_RETURN, reading "claims: cryptorecoverytrust.com."
Key numbers
- 40.71 BTC (~$3.31 million) moved in one transaction on Sept. 21.
- A broader sweep pulled 52.37 BTC from several attacker clusters into a fresh address flagged for the same trust.
- That 52.37 BTC represents roughly 2.8% of the total exploit.
- At its peak, the Coldcard exploit reached about $130 million across thousands of addresses.
What the data shows
Blockchain researcher Alex Thorn, head of research at Galaxy, shared details of the movement. He said the white-hat funds came from attacker clusters labeled "Footprint AA" and a second-wave hop from the hack. The transaction appeared in block 967,948.
Thorn noted that the 52.37 BTC sent to the trust is only a small fraction of the total haul. Much of the stolen Bitcoin had sat untouched in attacker wallets for weeks.
How the Coldcard exploit happened
The exploit traces back to a March 2021 firmware build error on Coinkite's Coldcard devices. The flaw caused the devices to generate seed phrases with too little randomness, making private keys guessable. Because the problem was built into how the seed was created, simply updating the firmware could not fix wallets already generated on a compromised device.
A seed phrase is a set of words used to restore a crypto wallet. If someone can guess it, they can steal the funds in that wallet.
What is still unclear
The on-chain messages did not explain how the Crypto Recovery Trust would operate or how victims could claim their coins. No details were provided about who is running the effort or what process claimants would need to follow.
Why it matters
The Coldcard exploit is one of the largest self-custody disasters in recent crypto history. For victims, even a small recovery like 2.8% of the stolen funds offers some hope. It also shows that blockchain tracking can sometimes trace stolen coins even after they have sat dormant for a long time.
Coinkite has previously told exposed users to move to newly generated seeds and has rolled out new security measures after the breach.
What happens next
The movement of funds toward a recovery trust suggests at least some parties are trying to return coins to victims. Whether more funds will follow and how the trust will handle claims remains to be seen.