COLDCARD white hats transfer 52 BTC to Crypto Recovery Trust for victim reimbursement

3 hours ago 33

A group of white-hat researchers has moved 52.37 BTC from wallets compromised in the COLDCARD exploit to a recovery address controlled by the Crypto Recovery Trust. The transfer, which occurred around block 967,948, represents roughly 2.8% of the total funds drained during the attack.

The COLDCARD exploit saw attackers siphon off an estimated 1,500+ BTC, with total losses surpassing $100 million. Starting on July 30, 2026, attackers drained approximately 594 BTC within minutes from exposed wallets. The speed suggested automated tooling, likely scripts scanning the blockchain for addresses generated with the faulty entropy and sweeping them in bulk.

How the recovery operation works

The effort was partly organized by DART, the Digital Asset Recovery Trust, which identified vulnerable address clusters tied to the COLDCARD entropy flaw. Researchers scanned for wallets still exposed to the vulnerability and moved recoverable funds before malicious actors could beat them to it.

The consolidated transaction included an OP_RETURN message, a way to embed data directly into the Bitcoin blockchain, directing affected users to cryptorecoverytrust.com to file claims.

DART had reportedly secured over 50 BTC by late July 2026, parking it in the Crypto Recovery Trust. That trust is a Wyoming-based statutory entity advised by Steptoe LLP, a major international law firm. Its stated mission is to document recoveries, segregate assets from any operational funds, and verify rightful ownership before releasing anything.

The white-hat researchers involved did not seek bounties for their work. Recovered funds are held separately within the trust, a deliberate structural choice meant to prevent commingling and establish a clear chain of custody for eventual disbursement.

The firmware flaw that started it all

The vulnerability traces back to a firmware build error in certain COLDCARD hardware wallet models. The flaw compromised the device’s hardware random-number generator, the component responsible for producing the entropy that underpins seed phrase generation. That predictability meant attackers could potentially reconstruct compromised seed phrases offline, no network access or sophisticated hacking infrastructure required.

Coinkite, the company behind COLDCARD, acknowledged the issue and released emergency firmware updates. The firmware build error reportedly originated in a March 2021 update, meaning some wallets had been silently vulnerable for over five years before the exploit was carried out.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article