{"id":37491,"date":"2026-09-22T08:42:40","date_gmt":"2026-09-22T08:42:40","guid":{"rendered":"https:\/\/bitunikey.com\/news\/coldcard-whitehats-move-52-37-btc-to-recovery-trust\/"},"modified":"2026-09-22T08:43:07","modified_gmt":"2026-09-22T08:43:07","slug":"coldcard-whitehats-move-52-37-btc-to-recovery-trust","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/coldcard-whitehats-move-52-37-btc-to-recovery-trust\/","title":{"rendered":"Coldcard whitehats move 52.37 BTC to recovery trust"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Whitehat operators have moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust created to return rescued Bitcoin to verified owners.<\/p>\n<div id=\"cn-block-summary-block_37479fc914df0be9cdfb234278175e99\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Whitehat operators moved 52.37 BTC linked to Coldcard exploit wallets into a recovery trust address.<\/li>\n<li>The transfer represented 2.8% of tracked exploit funds, according to Galaxy Digital researcher Alex Thorn.<\/li>\n<li>Crypto Recovery Trust says verified owners can submit claims and provide evidence for returned assets.<\/li>\n<li>Coinkite says patched firmware fixes future seed generation but cannot repair already weakened wallet seeds.<\/li>\n<li>Current recommended Coldcard firmware is version 5.6.2 for Mk4\/Mk5 and 1.5.2Q for Q devices respectively.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Galaxy Digital Head of Research Alex Thorn <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/intangiblecoins\/status\/2102114798833946783\" target=\"_blank\">said<\/a> the Bitcoin came from the tracked Wave 2 cluster and footprints labeled AA, AU and AX, with the consolidation recorded in Bitcoin block 967,948. Thorn said the amount represented 2.8% of the exploit funds his team was tracking.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u2744\ufe0fCOLDCARD WHITE HAT MOVES FUNDS TO TRUST \ud83c\udff3\ufe0f<\/p>\n<p>52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN &#8220;claim:cryptorecoverytrust dot com&#8221; in block 967,948<\/p>\n<p>these white hatted funds represent 2.8% of the coldcard exploit <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/t.co\/c5eYeQMxHQ\">pic.twitter.com\/c5eYeQMxHQ<\/a><\/p>\n<p>\u2014 Alex Thorn (@intangiblecoins) <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/intangiblecoins\/status\/2102114798833946783?ref_src=twsrc%5Etfw\">September 21, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The destination transaction carried an OP_RETURN message pointing to \u201cclaim:cryptorecoverytrust dot com,\u201d according to Thorn. Galaxy Research separately identified activity in the same block involving 20 inputs and 480 outputs and published transaction ID 38b524ccb8ca260ec705ab980982144857c477658fa39591870ee8cb09bcea47.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Coldcard recovery moves rescued Bitcoin into a trust<\/strong><\/h2>\n<p>The transfer places part of the recovered Bitcoin under the Crypto Recovery Trust, a Wyoming statutory trust established to hold digital assets recovered from compromised wallets while ownership claims are checked.<\/p>\n<p>Crypto Recovery Trust <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cryptorecoverytrust.com\/?utm_source=chatgpt.com\" target=\"_blank\">states<\/a> that its role is to reunite recovered assets with their rightful owners through a formal claims process. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and names Agentic Trace LLC as trustee.<\/p>\n<p>The Digital Asset Recovery Trust, or DART, had already disclosed recovery work connected with the Coldcard incident before the latest consolidation. DART <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/assetrecovery.io\/blog\/coldcard-entropy-recovery.html?utm_source=chatgpt.com\" target=\"_blank\">reported<\/a> that it and independent whitehat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving the funds before malicious actors could reach them.<\/p>\n<p>DART said recovered Bitcoin was placed in the trust instead of researcher-controlled wallets or operational accounts. Its process includes blockchain analysis, proof-of-ownership checks and sanctions screening before assets can be returned. Funds involving competing claims, sanctions restrictions or criminal proceedings may follow separate legal procedures.<\/p>\n<p>The Sept. 21 movement provides a newer on-chain view of those recovery efforts. Thorn tied the 52.37 BTC specifically to previously identified exploit clusters, while describing them as whitehat-controlled funds. His 2.8% calculation refers to Galaxy\u2019s tracked exploit total and should not be read as an official Coinkite loss figure.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Coldcard exploit began with a seed-generation flaw<\/strong><\/h2>\n<p>The Coldcard incident began July 30 after attackers exploited weakened Bitcoin wallet seeds created by affected firmware. Coinkite\u2019s current incident record <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/coldcard.com\/security\/status?utm_source=chatgpt.com\" target=\"_blank\">explains<\/a> that a firmware integration defect caused the seed-generation path to resolve to MicroPython\u2019s Yasmarang software pseudorandom generator instead of the intended hardware random number generator.<\/p>\n<p>Attackers did not need to remotely control the hardware wallets. Coinkite says they regenerated vulnerable private keys offline after the reduced randomness made affected seed phrases easier to search. The company describes the incident as a firmware seed-generation failure, not a remote takeover of Coldcard devices.<\/p>\n<p>Independent technical research has traced the weakness to firmware changes dating from 2021. One public investigation estimated that older Mk3 devices could produce roughly 40 bits of effective entropy under affected conditions, while Mk4, Mk5 and Q models retained approximately 72 bits instead of the intended security level.<\/p>\n<p>Early losses were smaller than the totals later associated with multiple attack waves. As crypto.news previously reported, the Coldcard firmware build error and first-wave Bitcoin losses involved roughly 594 BTC taken from around 500 wallets within approximately 25 minutes.<\/p>\n<p>Later tracking identified additional wallets and attack waves. A separate crypto.news investigation into the five-year Coldcard entropy flaw and four attack waves estimated 1,816 BTC had moved from more than 5,200 addresses as analysts expanded the identified scope.<\/p>\n<p>Loss estimates therefore vary depending on which attack waves, clusters and recovery transactions are included. Coinkite\u2019s current security status page does not publish a single definitive total for all stolen Bitcoin.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Coinkite says firmware updates cannot repair old seeds<\/strong><\/h2>\n<p>Coinkite released emergency fixes on July 31 for affected firmware lines. The company\u2019s download archive <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/coldcard.com\/downloads\/all?utm_source=chatgpt.com\" target=\"_blank\">shows<\/a> Mk4\/Mk5 version 5.6.0 and Q version 1.5.0Q as the first standard releases correcting future seed generation, while separate patches covered older Mk2\/Mk3 devices and Edge firmware.<\/p>\n<p>Security work continued after the initial patch. Current recommended standard releases are Mk4\/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4\/Mk5 and 6.6.1QX for Q.<\/p>\n<p>Coinkite stresses that installing fixed firmware does not change an existing seed. A wallet generated under vulnerable firmware can remain exposed even after the device receives the latest update because the weakness exists in the seed itself.<\/p>\n<p>Users with affected seeds are instructed to generate a corrected replacement seed and migrate funds, unless they meet the company\u2019s stated independent-dice exception. Coinkite says at least 50 fair, independent and privately recorded six-sided dice rolls added under the relevant workflow provide at least 128 bits of additional entropy, though users uncertain about the conditions are told to migrate.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Victims can submit ownership claims to the recovery trust<\/strong><\/h2>\n<p>The recovery process now centers on verifying who controlled addresses from which whitehats swept Bitcoin. Crypto Recovery Trust lets claimants search for recovery information, track a submitted claim and provide additional supporting evidence through its website.<\/p>\n<p>DART says the trust was structured to segregate recovered Bitcoin from researcher and operating funds while ownership is established. Attorneys from Steptoe\u2019s national security practice advise the trustee, according to DART\u2019s disclosure, because some returned assets may require sanctions, law-enforcement or competing-ownership reviews.<\/p>\n<p>The whitehat researchers involved in DART\u2019s earlier recovery work did not request a bounty, according to the organization. DART said other vulnerable assets and possible recovery leads remained under review after its August tally, leaving open the possibility that further Coldcard-linked funds could enter the claims process.<\/p>\n<p>For wallets that still rely on seeds created under affected Coldcard firmware, Coinkite\u2019s current instructions remain unchanged: install and verify a fixed firmware release, create a new seed under the corrected process, and move funds away from the vulnerable seed.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Whitehat operators have moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a recovery trust created to return rescued Bitcoin to verified owners. Summary&hellip;<\/p>\n","protected":false},"author":1,"featured_media":10067,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-37491","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=37491"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37491\/revisions"}],"predecessor-version":[{"id":37492,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37491\/revisions\/37492"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/10067"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=37491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=37491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=37491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}