White-hat operators move 52 Bitcoin from Coldcard exploit to Wyoming recovery trust.

The first theft wave, on July 30, drained 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC—valued at about $70.2 million at the time. Roughly 594 BTC from about 500 wallets was consolidated into one address within 25 minutes.
Coinkite estimated that the flawed software fallback reduced effective entropy to roughly 40 bits on Coldcard Mk3 devices and about 72 bits on the Mk4, Mk5 and Q, compared with 128 bits for a standard 12-word BIP-39 seed.
The vulnerability involved the Yasmarang deterministic pseudorandom number generator, which was seeded from the device’s unique ID and timer registers; researchers said attackers could reproduce candidate wallet seeds offline by constraining those variables and the device’s prior random-number-generator call history.
The recovery trust is legally identified as the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC named as trustee. Its process includes blockchain analysis, proof-of-ownership checks and sanctions screening; assets subject to competing claims, sanctions restrictions or criminal proceedings may be handled through separate legal procedures.
The Digital Asset Recovery Trust said it and independent white-hat researchers had already secured just over 50 BTC by Aug. 17, placing the recovered funds in the trust rather than in researchers’ personal wallets or operational accounts.
White-hat hackers have moved 52.37 Bitcoin into a Wyoming recovery trust after rescuing the funds from the Coldcard wallet exploit, according to Galaxy Digital. The transfer occurred in Bitcoin block 967,948 and represents 2.8% of the tracked exploit funds. A firmware flaw in Coldcard devices had weakened wallet security, making seeds vulnerable to theft—and attackers stole roughly $130 million in Bitcoin across multiple waves in July 2026.
Roughly 40% of the second wave of stolen Bitcoin has now been secured by white-hat researchers and placed into the Crypto Recovery Trust for return to verified owners, Alex Thorn of Galaxy Digital reported. Victims can search the trust's website to claim their wallets. Meanwhile, about $150 million in stolen Bitcoin remains in attacker-controlled accounts.
Coldcard devices accidentally used weak software randomness instead of their hardware random-number generator, according to manufacturer Coinkite. The flaw, hidden since March 2021, reduced seed entropy to roughly 40 bits on older Mk3 devices and 72 bits on newer Mk4, Mk5, and Q models—far below the 128-bit standard for safe wallet seeds. Attackers exploited this weakness to reconstruct seeds offline by guessing device variables.
On July 30, 2026, hackers executed the first attack wave, draining 1,082.65 Bitcoin from 1,196 wallet addresses in just 41 minutes—a haul worth roughly $70.2 million at the time, Galaxy Digital reported. Within 25 minutes, attackers had consolidated 594 Bitcoin from about 500 wallets into a single address. Follow-up attacks in subsequent weeks added more losses, bringing the total to approximately 1,830 Bitcoin across more than 9,000 addresses.
Security researchers began moving funds to safety in late July, before attackers could drain them, according to CryptoNews. By August 17, independent white-hat operators had rescued just over 50 Bitcoin. The latest transfer of 52.37 Bitcoin into the Recovered Digital Asset Statutory Trust of Wyoming—with Agentic Trace LLC serving as trustee—represents the largest single recovery so far. The trust is conducting ownership checks, identity verification, and sanctions screening before returning funds to victims.
The recovery trust operates a website where Coldcard owners can search their wallet addresses to check if their Bitcoin was rescued, CryptoNews reported. Victims must provide proof of ownership and pass identity and compliance checks. The process is necessary because both attackers and white-hat researchers generated the same private keys—making off-chain identity verification the only way to separate legitimate owners from thieves. About $150 million in stolen Bitcoin remains in attacker-controlled wallets across multiple theft waves.
Publishers
105
Articles
122
Reach
227