
Nearly two months after the massive hack linked to a firmware flaw, a portion of the stolen funds was placed in a legal trust in Wyoming to be returned to victims.
More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.
AI-generated summary
A firmware flaw on Coldcard wallets led to the theft of more than 1,830 BTC in late July.
Finally some good news in the Coldcard file. Nearly two months after the Coldcard breach which siphoned off more than 1,800 BTC from wallets deemed tamper-proof, 52.37 bitcoins have just taken the opposite path. They are now in a Wyoming legal trust responsible for returning them to their owners. The loot is worth around $4.5 million at today's rate. You still have to knock on the right door without falling into a new trap.
Key points:
On September 21, whitehats bundled 52.37 BTC linked to the hack at a Crypto Recovery Trust address.
According to Galaxy Research, nearly 40% of second wave funds were taken by security researchers, not thieves.
Victims prove they control their address by signing a message, without ever delivering their recovery phrase.
Updating your Coldcard does not protect a seed created with the old firmware.
Hack Coldcard: the hackers were not alone at the time
Back to July 30. In 25 minutes, 594 BTC leaves around 500 Coldcard addresses. The cause? A firmware defect caused the seeds (the recovery phrase that gives access to funds) to be generated from an all-too-predictable software random source instead of the dedicated chip, which made the keys guessable by brute force. Subsequent waves brought the addition to around 1,830 BTC according to Galaxy Research.
Except that not everyone was dumping these addresses for the same purpose. According to Alex Thorn, director of research at Galaxy, cited by CoinDesk on September 22, around 40% of bitcoins in the second wave were swept away by ethical hackers. These whitehats exploit the loophole before the criminals to protect the money.
The September 21 transfer, confirmed in block 967,948, brings together 30.19 BTC from this second wave, 17.98 BTC from a group of addresses called AX and a few crumbs from two others. Added to this are around 3 BTC with no known history, which Thorn attributes to other Coldcard rescues without being able to confirm it. It all landed on an address marked with an OP_RETURN message, a text inscription engraved in the blockchain, which links to cryptorecoverytrust.com.
Who holds the keys to the Coldcard bitcoin vault
First reflex, distrust. An address that invites you to “claim” lost funds looks exactly like scams that target hacking victims. On paper, however, this arrangement holds up. The Crypto Recovery Trust is a Wyoming statutory trust (Recovered Digital Asset Statutory Trust of Wyoming) whose trustee is Agentic Trace LLC. Lawyers from the national security division of the Steptoe firm advise him. DART, a structure specializing in the recovery of digital assets, coordinated the rescues and already claimed “a little more than 50 BTC” secured as of August 17.
No one will ask you for your seed. DART specifies it in black and white: no recovery phrase, no private key, no PIN code, only addresses and transaction identifiers. To prove control of an address, the applicant signs a unique message with keys that never leave their home. The trust then verifies the ownership and origin of the funds and screens the applicants through sanctions lists before any restitution. The site also ensures that it does not charge any fees.
Victims of the Coldcard hack: the right reflexes before claiming
If your bitcoins disappeared between the end of July and the end of August, type the site address yourself rather than clicking on a link received by message or email, then search for your addresses in the trust database. Fake recovery services sprout up like mushrooms after every hack, and this one will be no exception. A request for a recovery phrase or “unblocking fee” is a sure sign of a scam.
Another trap, more devious. Many owners think they are out of the woods because their Coldcard is running the latest firmware. Coinkite has nevertheless hammered it home: an update does not repair a seed generated by the defective version. If yours was created on a Mk2 or Mk3 before the patch, you must generate a new one and transfer your funds to it, whether your coins were affected or not.

The Services and Payment Agency confirms a data leak via fraudulent access to a user account on August 27, 2026, detected the next day. More than 143,000 people would be affected according to FrenchBreaches, with 2023-2024 payment notices from the Île-de-France “Coup de Pouce Energie” system containing names, addresses, IBAN/BIC, beneficiary numbers and amounts paid. This is the second such leak at ASP in five months.

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

Anthropic unveiled Claude Opus 5.5, sold 40% cheaper, followed immediately by OpenAI and its new GPT-6 Sol and Luna models at knockdown prices. This price war comes as Anthropic's IPO on Nasdaq approaches.

X deploys X Numbers, private codes allowing you to receive messages and calls from untracked accounts without revealing your phone number, thus paving the way for the X Money payment service.