started · updated
White-hat hackers move 52 BTC to Coldcard recovery trust
White-hat hackers have successfully moved 52.37 BTC, valued at over $4.5 million, into a recovery address associated with the Wyoming-based Crypto Recovery Trust. This action aims to secure funds from the Coldcard hardware wallet exploit before they can be stolen by malicious actors.
The recovered Bitcoin represents approximately 2.8% of the total funds linked to the Coldcard exploit, which has seen total losses estimated between $100 million and $154 million. The vulnerability originated from a firmware flaw in Coinkite’s Coldcard devices that compromised the entropy used for seed phrase generation, making private keys predictable.
Galaxy Digital researcher Alex Thorn noted that the transferred funds were consolidated from several attacker clusters, including those labeled as Wave 2 and Footprints AA, AU, and AX. The transaction included an OP_RETURN message directing affected users to the Crypto Recovery Trust website to file claims. While Coinkite has released firmware patches to prevent future issues, users with already compromised seeds are advised to migrate their funds to new devices.
Entities
Alex Thorn · Coinkite · Coldcard · Crypto Recovery Trust · Digital Asset Recovery Trust · Galaxy Digital · Steptoe LLP