Crypto iconCryptoSep 22, 2026 ~7 min source read

Whitehat operators move 52.37 BTC from Coldcard exploit wallets into a recovery trust

Researchers trace 52.37 BTC consolidated into a Wyoming statutory trust set up to verify ownership claims and return recovered funds to affected Coldcard users; the move represents part of wider recovery and investigation efforts after a seed-generation firmware flaw.

Coldcard whitehats move 52.37 BTC to recovery trust

Share this story

Send the public story page.

Useful takeaways from this story.

52.37 BTC linked to the Coldcard exploit was moved into the Crypto Recovery Trust to process verified ownership claims.

Galaxy Digital traced the transfer to previously identified exploit clusters and said the amount equals 2.8% of the exploit funds it tracked.

Coinkite patched the seed-generation flaw for future devices, but firmware updates cannot repair already weakened wallet seeds.

# What happened Whitehat operators consolidated 52.37 BTC tied to the July Coldcard wallet exploit into an address associated with a recovery trust. Galaxy Digital researcher Alex Thorn linked the bitcoins to previously tracked exploit clusters and found an OP_RETURN message in the destination transaction that pointed to the recovery trust's claims site.

# Why the transfer matters The moved funds were placed into the Crypto Recovery Trust, a Wyoming statutory trust set up to hold recovered digital assets while ownership claims are verified. The trust identifies itself legally as the Recovered Digital Asset Statutory Trust of Wyoming and names Agentic Trace LLC as trustee. The trust's stated process includes blockchain analysis, proof-of-ownership checks and sanctions screening prior to returning assets.

Galaxy Digital's analysis tied the 52.37 BTC to the Wave 2 cluster and footprints labeled AA, AU and AX. They recorded the consolidation in Bitcoin block 967,948 and calculated that amount as 2.8% of the exploit funds their team was tracking. That 2.8% figure reflects Galaxy's tracked total and is not a Coinkite loss estimate.

# Context: the Coldcard firmware seed-generation flaw The incident began July 30 when attackers exploited weakened wallet seeds produced by affected Coldcard firmware. Coinkite explains the problem as a firmware integration defect: a seed-generation path resolved to MicroPython's Yasmarang pseudorandom generator instead of the intended hardware random number generator. That meant reduced randomness in some generated seed phrases.

Coinkite says attackers did not remotely control devices. Instead, they regenerated vulnerable private keys offline after the weakened randomness made affected seed phrases easier to search. Independent technical research traced the weakness to firmware changes dating back to 2021. One public estimate suggested older Mk3 devices produced roughly 40 bits of effective entropy under affected conditions, while Mk4, Mk5 and Q models retained about 72 bits instead of the intended security level.

# Coinkite's response and firmware status Coinkite issued emergency firmware fixes on July 31 for affected lines. The company's download archive lists Mk4/Mk5 version 5.6.0 and Q version 1.5.0Q as the initial fixes. Current recommended firmware versions cited for devices are 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q models. Coinkite stresses that firmware updates prevent future weak seed generation but cannot repair seeds already weakened and used to derive private keys.

# The recovery work and follow-up procedures

The Sept. 21 movement into the trust offers an updated on-chain view of those recovery efforts, and Galaxy Digital published transaction data tying the moved BTC to known exploit clusters. The recovery trust mechanism provides a central legal vehicle for coordinating returns to verified owners while limiting direct custody by individual researchers.

# What to watch next

  • Any legal actions or competing claims that affect disposition of recovered funds.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app