Coindesk White Hats Recover 52 BTC from Coldcard Exploit to Crypto Recovery Trust
Article Content
- •52.37 BTC recovered from Coldcard exploit transferred to Crypto Recovery Trust.
- •The exploit used weak software-based randomness, leading to over $100 million in losses.
- •Victims can verify if their funds are secured by the recovery trust.
On September 22, 2026, white-hat hackers transferred 52.37 Bitcoin linked to the Coldcard hardware wallet exploit to the Crypto Recovery Trust in Wyoming. This exploit, which began on July 30, 2026, exploited a firmware flaw that caused wallets to generate weak seeds, leading to over $100 million in losses across 1,816 BTC. The vulnerability resulted from a firmware integration error that used a software-based pseudorandom number generator instead of hardware randomness. Galaxy Digital reported that the transferred amount represents about 2.8% of the total tracked exploit funds. Victims can check if their wallets are affected via the trust's website. The recovery effort has been ongoing, with white hats securing a significant portion of the stolen funds before they could be accessed by attackers. The exploit has raised concerns about the security of hardware wallets and the need for users to migrate to new seeds.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Coinkite in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…