Skip to content
White Hats Move 52.37 Bitcoin From Coldcard Exploit to Crypto Recovery Trust

White Hats Move 52.37 Bitcoin From Coldcard Exploit to Crypto Recovery Trust

Newscord September 22, 2026

52.37 BTC moved to Crypto Recovery Trust for victim restitution. Transfer recorded with OP_RETURN 'claim:cryptorecoverytrust dot com'.

How much of the tracked exploit the white hats swept .

8 of 9 outlets skipped it: coinkite says updating firmware does not repair existing seeds .

Same story, two versions

tap a side to read it in full

“ 40% of the Bitcoin associated with the second wave was swept by white hats to protect victims’ funds. ”

“ The trust now holds roughly 2.8% of the exploit funds Galaxy is tracking. ”

One outlet frames by wave , the other by tracked-total .

52 BTC to Wyoming trust

White-hat operators moved 52.37 bitcoin tied to the July Coldcard hardware wallet exploit into an address associated with the Crypto Recovery Trust, according to Galaxy Digital head of research Alex Thorn. Thorn said the destination transaction carried an OP_RETURN message reading "claim:cryptorecoverytrust dot com" and that the transfer was recorded in Bitcoin block 967,948. Thorn described the 52.37 BTC as part of a sweep of Wave 2 cluster funds, and he said the amount represented 2.8% of the total tracked exploit funds.

“ "Updating the firmware does not change or repair an existing seed." ”

Thorn also said 3.0134 BTC included in the transfer came from addresses Galaxy had not previously tracked, while he said the origin of those coins remained unconfirmed. Coinkite’s advisory said, "Updating the firmware does not change or repair an existing seed."

Why seeds were guessable

Coinkite’s incident record described the Coldcard problem as a firmware seed-generation failure, where a firmware integration defect routed seed generation to MicroPython’s Yasmarang software pseudorandom generator instead of the device’s hardware random number generator. The vulnerability let attackers reconstruct wallet seeds offline, because the reduced randomness narrowed the range of possible private keys. Coinkite’s advisory said affected users must migrate to a new seed, and it said a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone.

Security researcher Nick Bax said he helped rescue 50 bitcoin at the end of July because the funds were "imminently going to be stolen" due to the Coldcard entropy flaw. The Crypto Recovery Trust website process let potential victims enter their wallet addresses to determine whether the trust controls their funds.

Recovery totals still vary

TRM Labs said 1,816 BTC remained in attacker wallets across four theft waves, while Galaxy Digital tracked a different total and said the 52.37 BTC transfer represented 2.8% of its tracked exploit funds. Cointelegraph reported that white hats secured 40% of the Bitcoin moved in the Coldcard exploit’s second wave, transferring it to a Wyoming trust for victims. C Galaxy Digital head of research Alex Thorn cited a published total of 1,830 BTC across 9,162 addresses linked to the Coldcard vulnerability.

“ 1,816 BTC remains in attacker wallets across four theft waves. ”

The Crypto Recovery Trust identified its legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and named Agentic Trace LLC as trustee, while the trust said verified owners can submit claims and provide evidence for returned assets. The sources also said loss estimates vary depending on which attack waves, clusters, and recovery transactions are included, and Coinkite’s security status page does not publish a single definitive total for all stolen Bitcoin.

Extracted Entities