White-hat actors move stolen Bitcoin from Coldcard exploit toward recovery trust
Quick Look
- White-hat actors have moved 40.71 BTC worth $3.31 million from the Coldcard hardware wallet exploit into a recovery effort labeled 'Crypto Recovery Trust,' according to Galaxy Research.
- The funds represent 2.8% of the total $130 million theft stemming from a 2021 firmware flaw that generated weak seed phrases on Coinkite devices.
AI-generated summary
Why It Matters
The Coldcard exploit originated from a March 2021 firmware build error on Coinkite's Coldcard devices that generated seed phrases with insufficient randomness, making private keys guessable. The flaw was embedded in the seed creation process, so firmware updates could not fix already-generated wallets.
Some of the Bitcoin stolen in the sprawling Coldcard hardware wallet exploit is being routed toward a recovery effort, with white-hat actors moving funds into what they've labeled a trust for returning the coins.
According to Galaxy Research's blockchain monitoring, 40.71 BTC, worth about $3.31 million, was moved on Sept. 21 in a single transaction that consolidated coins tied to the exploit.
The transfer, spanning 11 addresses across 20 inputs and 480 outputs, carried an OP_RETURN message, a small note embedded in a Bitcoin transaction, reading "claims: cryptorecoverytrust.com." Galaxy attributed the coins to attackers it had tagged as "Footprint AA" and a second-wave hop from the hack.
In a related post, Galaxy's head of research Alex Thorn said a broader sweep pulled 52.37 BTC, drawn from several attacker clusters, into a fresh address flagged for the same Crypto Recovery Trust.
He noted the white-hatted funds represent roughly 2.8% of the total Coldcard exploit, a fraction of the haul that has otherwise remained largely dormant in attacker wallets.
The movement marks a notable turn in one of the year's largest self-custody disasters. The Coldcard exploit stemmed from a March 2021 firmware build error on Coinkite's Coldcard devices that generated seed phrases with far too little randomness, leaving private keys guessable. Because the flaw was baked into how the seed was created, updating the firmware couldn't fix a wallet already generated on a compromised device.
At its peak, the theft grew to roughly $130 million across thousands of addresses, with Galaxy tracking the sweeps as they unfolded in waves. Much of the stolen Bitcoin had sat untouched in attacker addresses for weeks, prompting speculation about whether any of it would ever move.
The appearance of a recovery-trust label suggests at least some parties are attempting to shepherd funds back to victims, though the specifics of how the Crypto Recovery Trust would operate, and how owners might claim their coins, weren't detailed in the on-chain messages.
What to Watch
AI outlook — possibilities, not facts
Additional amounts of stolen Bitcoin will be moved toward the Crypto Recovery Trust in the coming weeks
Possible · Within weeks
Open Questions
- How will the Crypto Recovery Trust operate and verify ownership claims?
- What percentage of the total stolen Bitcoin might eventually be recovered?
- Are there legal or regulatory implications for the white-hat actors moving the funds?







