Whitehats Move 52.37 Bitcoin (BTC) From Coldcard Exploit Wallets Into Recovery Trust
Whitehat operators moved 52.37 BTC linked to the July Coldcard exploit into a Wyoming recovery trust, 2.8% of tracked funds, confirmed in block 967,948.
AI SummaryAI
- Alex Thorn said the transfer equals 2.8% of Galaxy's tracked exploit funds.
- The consolidation confirmed in Bitcoin block 967,948 with an OP_RETURN claims message.
- Coldcard exploit began July 30 via Yasmarang software PRNG replacing hardware randomness.
- Estimated losses exceed $100 million across waves totaling roughly 1,816 BTC.
Whitehat operators moved 52.37 Bitcoin (BTC) out of addresses drained in July’s Coldcard hardware-wallet exploit and consolidated the coins into a fresh address tied to a recovery trust built to hand them back to verified owners, on-chain tracking shows. Galaxy Digital’s head of research Alex Thorn laid out the sweep, saying the funds came from the tracked Wave 2 cluster together with footprints labeled AA, AU and AX. The consolidation was confirmed in Bitcoin block 967,948, and the destination transaction carried an OP_RETURN message reading “claim:cryptorecoverytrust dot com.” Thorn calculated that the 52.37 BTC represents 2.8% of the exploit funds his team is tracking, and that roughly 40% of Wave 2 has now been identified as whitehat activity rather than theft. An additional 3.0134 BTC with no prior tracking history also reached the trust address in the same transaction, which Thorn flagged as presumably more recovered coins but left unconfirmed. The destination is the Crypto Recovery Trust, whose legal form is the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC named as trustee. The entity’s stated role is to reunite recovered Bitcoin assets with their rightful owners through a formal claims process covering blockchain analysis, proof-of-ownership checks and sanctions screening. A separate recovery vehicle, the Digital Asset Recovery Trust (DART), had already disclosed before this week’s consolidation that it and independent whitehats secured just over 50 BTC from vulnerable addresses as of Aug. 17, placing the coins in trust custody rather than researcher-controlled wallets. Funds tied to competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures, and movements of this size would ordinarily be tagged as whale transfers rather than recoveries. Thorn’s 2.8% figure refers to Galaxy’s tracked total and should not be read as an official Coinkite loss number.
The seed-generation flaw behind the drain
The Coldcard incident began July 30, when attackers started exploiting weakened wallet seeds produced by affected firmware. Coinkite’s incident record explains that a firmware integration defect caused the seed-generation path to resolve to MicroPython’s Yasmarang software pseudorandom generator instead of the intended hardware random number generator. The attackers did not need to remotely control the devices: once the reduced randomness made affected seed phrases easier to search, they simply regenerated the vulnerable private keys offline. Independent technical research traced the weakness to firmware changes dating from 2021 and estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under the affected conditions, while Mk4, Mk5 and Q models retained about 72 bits — far below the intended security level. Early losses were modest compared with the totals that emerged later. The first wave stripped roughly 594 BTC from around 500 wallets in approximately 25 minutes, and as analysts expanded the identified scope across four attack waves, tracking grew to about 1,816 BTC moved from more than 5,200 addresses, with estimated losses exceeding $100 million. Coinkite shipped emergency fixes on July 31 — version 5.6.0 for Mk4/Mk5 and 1.5.0Q for Q devices, alongside patches covering older Mk2/Mk3 hardware — and its current recommended standard releases are 5.6.2 and 1.5.2Q, both issued Sept. 3. The company stresses that the patches correct future seed generation only: a wallet created under vulnerable firmware remains exposed even on a fully updated device, because the weakness lives in the seed itself. Owners of affected seeds are told to generate a corrected replacement and migrate their funds, unless they meet the stated independent-dice exception, under which at least 50 fair, privately recorded six-sided dice rolls add at least 128 bits of entropy; anyone uncertain is told to move. Every recovery consolidation is now traceable on Bitcoin’s proof-of-work ledger, which doubles as the shared evidence layer for the cleanup.
On-chain trail backs the claims process
COINOTAG’s reading: this episode stands out for its verifiability. The researcher published transaction ID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47, so anyone can independently confirm the sweep in block 967,948, while Coinkite’s own security status page states the root cause rather than deflecting. That pairing — primary on-chain evidence plus a formal trust structure with sanctions screening — sets a template for hardware-wallet incident response. For investors who prefer to hodl their own keys, seed generation is now demonstrably part of the attack surface, and custody tradeoffs against exchange solutions in our best crypto exchanges guide deserve a fresh look. Our Bitcoin coverage will track further trust claims as they land.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


