White-hat actors moved 40.71 BTC (~$3.31 million) tied to the Coldcard exploit on Sept. 21 in a transaction carrying a “crypto recovery trust” message.
Galaxy’s Alex Thorn said a broader sweep pulled 52.37 BTC from several attacker clusters into a fresh address flagged for the same trust—roughly 2.8% of the total exploit.
The exploit, which peaked around $130 million, stemmed from a March 2021 Coldcard firmware flaw that made seed phrases guessable.
Some of the Bitcoin stolen in the sprawling Coldcard hardware wallet exploit is being routed toward a recovery effort, with white-hat actors moving funds into what they’ve labeled a trust for returning the coins.
According to Galaxy Research’s blockchain monitoring, 40.71 BTC, worth about $3.31 million, was moved on Sept. 21 in a single transaction that consolidated coins tied to the exploit.
The transfer, spanning 11 addresses across 20 inputs and 480 outputs, carried an OP_RETURN message, a small note embedded in a Bitcoin transaction, reading “claims: cryptorecoverytrust.com.” Galaxy attributed the coins to attackers it had tagged as “Footprint AA” and a second-wave hop from the hack.
In a related post, Galaxy’s head of research Alex Thorn said a broader sweep pulled 52.37 BTC, drawn from several attacker clusters, into a fresh address flagged for the same Crypto Recovery Trust.
He noted the white-hatted funds represent roughly 2.8% of the total Coldcard exploit, a fraction of the haul that has otherwise remained largely dormant in attacker wallets.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN “claim:cryptorecoverytrust dot com” in block 967,948
The movement marks a notable turn in one of the year’s largest self-custody disasters. The Coldcard exploit stemmed from a March 2021 firmware build error on Coinkite’s Coldcard devices that generated seed phrases with far too little randomness, leaving private keys guessable. Because the flaw was baked into how the seed was created, updating the firmware couldn’t fix a wallet already generated on a compromised device.
At its peak, the theft grew to roughly $130 million across thousands of addresses, with Galaxy tracking the sweeps as they unfolded in waves. Much of the stolen Bitcoin had sat untouched in attacker addresses for weeks, prompting speculation about whether any of it would ever move.
BitcoinBTC · USD
$86,230+13%
Sep 15Sep 17Sep 19Sep 21Sep 22
$87.0k$83.2k$79.3k$75.5k
24h HighHigh$87,330
24h LowLow$85,107
VolVol$1.9B
Market projectionsOdds by Myriad
→
The appearance of a recovery-trust label suggests at least some parties are attempting to shepherd funds back to victims, though the specifics of how the Crypto Recovery Trust would operate, and how owners might claim their coins, weren’t detailed in the on-chain messages.
Coinkite has previously urged exposed users to migrate to newly generated seeds and rolled out new security measures in the wake of the breach.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.