Summary
- White-hat hackers transferred 40.71 BTC (approximately $3.31 million) linked to the Coldcard exploit on September 21, using a transaction labeled as a "crypto recovery trust."
- According to Alex Thorn from Galaxy, an additional 52.37 BTC was transferred from various attacker groups into a new address associated with the same recovery trust, amounting to about 2.8% of the total exploit.
- The exploit originated from a firmware vulnerability in Coldcard devices in March 2021, which allowed for the guessing of seed phrases.
Funds stolen during the extensive Coldcard hardware wallet exploit are now being funneled into a recovery initiative, with white-hat hackers designating these funds for the return of the stolen assets.
As reported by Galaxy Research's blockchain analysis, a transaction on September 21 moved 40.71 BTC, equivalent to around $3.31 million, consolidating coins associated with the exploit.
Myriad: Predict Bitcoin's Future Value Make your prediction here.This transaction involved 11 addresses with 20 inputs and 480 outputs, featuring an OP_RETURN message that stated, "claims: cryptorecoverytrust.com." Galaxy identified these coins as belonging to attackers labeled "Footprint AA" and indicated a secondary movement from the initial hack.
In a follow-up statement, Alex Thorn from Galaxy noted that a larger operation had retrieved 52.37 BTC from multiple attacker clusters into a newly flagged address for the Crypto Recovery Trust.
Thorn highlighted that these white-hat funds constitute roughly 2.8% of the total amount taken during the Coldcard exploit, which has largely remained inactive in the wallets of the attackers.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC from Wave 2, Footprints AA, AU, AX have been consolidated into a new address with an OP_RETURN message "claim:cryptorecoverytrust dot com" in block 967,948
these white-hat funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ
— Alex Thorn (@intangiblecoins) September 21, 2026
This development highlights a significant shift in one of the most notable self-custody incidents of the year. The Coldcard exploit was triggered by a firmware error in March 2021 on Coinkite's Coldcard devices, which produced seed phrases with insufficient randomness, making private keys vulnerable to guessing. Since this flaw was ingrained in the seed generation process, simply updating the firmware could not rectify wallets that were already compromised.
At its height, the theft reached approximately $130 million across numerous addresses, with Galaxy monitoring the movement of funds as it occurred in phases. Much of the pilfered Bitcoin had remained untouched in the attackers' wallets for an extended period, leading to doubts about whether any of it would ever be transferred again.
BitcoinBTC · USD$86,204+13%24H7D1M1YYTDSep 15Sep 17Sep 19Sep 21Sep 22$87.0k$83.2k$79.3k$75.5k24h HighHigh$87,33024h LowLow$85,107VolVol$1.9BMarket predictionsOdds by MyriadThis weekAbove $86,000Above $86k52% chanceThis monthAbove $86,000Above $86k52% chance→Buy Bitcoin with USDTPowered by Jupiter$50$100$500BuyPrice data by CoinGeckoCoinGeckoMore Bitcoin news and projections →The introduction of a recovery-trust label indicates that some individuals are attempting to facilitate the return of funds to the victims, although the details regarding the operation of the Crypto Recovery Trust and the process for owners to reclaim their coins remain unclear based on the on-chain messages.
Coinkite has previously advised affected users to transition to newly generated seeds and has implemented new security measures following the incident.
