Skip to content
Read the original ↗

Read the original ↗

www.altcoinbuzz.io • September 22, 2026

White hats moved 52.37 Bitcoin tied to the Coldcard entropy flaw into an address controlled by the Crypto Recovery Trust, a Wyoming statutory trust, on Monday. The transfer was recorded in Bitcoin block 967,948 and carried an OP_RETURN message pointing to claim:cryptorecoverytrust.com, according to Galaxy Digital head of research Alex Thorn.

For a Coldcard holder, the question is whether their seed is one of the ones that can be guessed. The trust now holds roughly 2.8% of the exploit funds Galaxy is tracking. The rest, 1,816 BTC according to TRM Labs, is still sitting in attacker-controlled addresses across four waves of theft that began on July 30, 2026.

What the bug actually is

The vulnerability is a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator. In plain terms: when a Coldcard created a new wallet, it was not generating keys from hardware randomness but from a software fallback seeded from the chip's unique ID and timer registers.

That fallback, called Yasmarang, produced a much smaller pool of possible seeds than a normal Bitcoin wallet. Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and 72 bits on the Mk4, Mk5 and Q, against 128 bits for a standard 12-word BIP-39 seed. Block, the security firm that traced the fault, says an attacker who can determine or sufficiently constrain the device UID, timer state and prior RNG-call history can reproduce candidate output streams offline, without ever touching the device.

Who got drained and how fast

The first wave hit on July 30. An attacker drained 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth $70.2 million at the time. Roughly 594 BTC moved out of 500 wallets into a single consolidation address within 25 minutes, according to TRM. Two more confirmed waves raised the observed total to 1,367.05 BTC across 4,585 addresses. TRM's wider tally, which counts a fourth wave, puts losses near 1,816 BTC (around $116 million) drained from more than 5,200 addresses.

Laundering has been limited so far: TRM notes a single 64.9 BTC Wasabi deposit and 200 ETH sent to Tornado Cash on August 4, 2026. Galaxy has reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators. TRM is not attributing the theft to a specific actor.

What the white hats did

Security researcher and SEAL 911 incident responder Nick Bax said on Sept. 9 that he helped rescue 50 BTC at the end of July because the funds were "imminently going to be stolen" due to the Coldcard entropy flaw. DART, the Digital Asset Recovery Trust, reported that it and independent white-hat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving them before malicious actors could reach them.

The Crypto Recovery Trust is the Wyoming entity that received the 52.37 BTC. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC as trustee. Potential victims can enter their wallet addresses on the trust's website to determine whether the trust controls their funds.

Coinkite's advisory is blunt: "Updating the firmware does not change or repair an existing seed." Affected users must migrate to a new seed, unless they qualify for the dice-entropy exception. Coinkite says a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone, and adds that funds controlled by seeds generated on affected firmware are at risk only if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. TAPSIGNER, OPENDIME and SATSCARD use different codebases and are unaffected.

What firmware is current

The current recommended standard releases are Mk4/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4/Mk5 and 6.6.1QX for Q. Vulnerable firmware versions include Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive, Mk4 and Mk5 before standard version 5.6.0 or Edge version 6.6.0X, and Q before standard version 1.5.0Q or Edge version 6.6.0QX.

The exact split of the 52.37 BTC between the second wave and other waves is not public. Galaxy confirmed 3.0134 BTC came from addresses it had not previously tracked but did not break the rest down further. The various trackers (Galaxy, TRM and The Hacker News) cite different totals because they are using different cluster methods, and Coinkite has not published a single official loss figure. No one has attributed the attack to a named actor. The Crypto Recovery Trust has not said when it was established or whether any funds have been returned to verified claimants.

Kalshi Files for Perpetual Futures on 58 US Stocks and ETFs

Kalshi filed Sept. 18 with the SEC (SR-KALSHIEX-2026-02) and the CFTC to list perpetual security futures on 58 US stocks and ETFs. CFTC approval pending.

CME adds UNI and BCH Futures to Crypto Derivatives

CME adds Bitcoin Cash and Uniswap futures on October 19, giving institutions restricted from offshore crypto venues a regulated route to both tokens.

Crypto-draining FOMO App was Live on Apple's App Store for 8 days

SlowMist found FOMO, a crypto-draining app, on Apple's App Store for 8 days. It exploited a WebKit flaw to steal seed phrases and private keys from iPhones.

Extracted Entities