Coldcard Flaw Exposed: Hackers Redirect Bitcoin to Recovery Trust

White-hat hackers move 52.37 BTC from Coldcard exploit into “Crypto Recovery Trust” address

White-hat hackers have moved 52.37 bitcoin linked to July’s Coldcard hardware wallet exploit into an address associated with a newly formed “Crypto Recovery Trust,” according to Galaxy Digital Head of Research Alex Thorn.

The transfer was confirmed in Bitcoin block 967,948 and included an OP_RETURN message reading: “claim:cryptorecoverytrust dot com”. Thorn said the coins were consolidated from “Wave 2” of the tracked exploit funds, along with three labeled footprints (AA, AU, and AX), before being sent to the trust-linked address.

The movement of funds suggests some compromised bitcoin is being swept by ethical actors with the intent of returning it to victims, rather than being retained by attackers. Thorn said the 52.37 BTC represents 2.8% of the total tracked exploit funds, and that roughly 40% of Wave 2 has now been identified as white-hat activity.

The same transaction also included an additional 3.0134 BTC that had no prior tracking history. Thorn said this is presumably additional white-hat-recovered Coldcard funds, though he stressed it remains unconfirmed.

The Coldcard incident began on July 30, with subsequent attack waves (labeled waves 1, 2, and 3 in tracking) that contributed to estimated losses of more than $100 million in bitcoin. The exploit stemmed from a weakness in how some wallets generated their seed phrases.

According to the description of the flaw, affected Coldcard devices could generate wallet seeds using weaker software-based randomness rather than the wallet’s dedicated hardware random number generator. That made some seeds vulnerable to reconstruction, enabling attackers to derive private keys and drain funds.

Coinkite, the maker of Coldcard, has since patched the firmware. However, the reporting notes that funds already exposed under the older, vulnerable seeds remain at risk regardless of the patch.

The recovery effort is centered around the Crypto Recovery Trust, described as a Wyoming statutory trust created to help reunite assets tied to the exploit with their rightful owners. Victims can check whether their wallet addresses are associated with recovered funds via the trust’s claim portal at cryptorecoverytrust.com.

  • What happened: 52.37 BTC tied to the Coldcard exploit was moved by white-hat operators to a trust-linked address.
  • Why it matters: It indicates active, organized recovery attempts for a portion of stolen funds, even as broader losses remain substantial.
  • Broader context: The exploit leveraged weak seed generation in certain circumstances, allowing attackers to reconstruct seeds and take funds; patching firmware does not retroactively protect already-compromised seeds.

Similar Posts

Leave a Reply