Some of the Bitcoin stolen in the Coldcard hardware wallet exploit is moving toward a recovery effort. On September 21, apparent white-hat actors consolidated 52.37 BTC — roughly $4.5 million — from several clusters tied to the attackers into a fresh address carrying an embedded label for a "Crypto Recovery Trust," according to on-chain monitoring by Galaxy Research.
The single largest move, per Decrypt, carried 40.71 BTC (about $3.31 million) across 11 addresses, consolidating 20 inputs into 480 outputs. The transaction included an OP_RETURN message — a short note inscribed in a Bitcoin transaction — reading "claims: cryptorecoverytrust.com." Galaxy attributed the coins to attacker clusters it had tagged as "Footprint AA" and a second-wave hop from the exploit.
Galaxy's head of research Alex Thorn said the broader sweep drew coins from Wave 2 and the Footprints AA, AU and AX clusters into a new address in block 967,948, and that the white-hatted funds represent roughly 2.8% of the total Coldcard exploit. Blockonomi and Bitcoin.com (via CoinSpectator) corroborated the figure, with the recovered coins now held under the trust label for victims to reclaim.
How white hats got there first
The rescue was possible because much of the stolen Bitcoin had sat dormant. The Coldcard exploit stemmed from a firmware build error introduced in March 2021 that generated seed phrases with far too little randomness, leaving private keys guessable. Because the flaw was baked into seed creation, a firmware update could not repair wallets already generated on a compromised device — but it also meant the vulnerable keys were, in principle, derivable by anyone who understood the entropy failure, white hats included.
At its peak, the theft reached roughly $130 million across thousands of addresses, with Galaxy tracking the attacker sweeps as they unfolded in waves. Manufacturer Coinkite urged exposed users to migrate to newly generated seeds and rolled out additional security measures in the aftermath, as Decrypt reported.
An unresolved claims process
How the Crypto Recovery Trust will operate — who runs it, how ownership will be proven, and when distributions might begin — was not detailed in the on-chain messages, and no independent verification of the trust's structure was available at the time of writing. Decrypt noted that the specifics of the claims process remain unknown.
That gap matters for victims. "Recovery" services are a established phishing vector after large incidents: World Mobile Chain issued similar warnings within days of its own bridge exploit this week, and fake claim portals routinely follow high-profile losses. Coldcard victims should treat any unsolicited contact, third-party claim site or "migration" link with suspicion, and watch for official communications through channels they control.
If the trust performs as its label suggests, the operation would mark the first meaningful recovery in one of the year's largest self-custody failures — and a rare instance where the same mathematics that broke a wallet were used to claw part of the haul back before the thieves could spend it.
TrustGrade tracks the security posture of wallet vendors and hardware manufacturers. Verified trust data: trustgrade.ai.