
Crypto · updated 1h ago · 2 min read
White Hats Move 52.37 Bitcoin From Coldcard Exploit to Crypto Recovery Trust
52.37 BTC moved to Crypto Recovery Trust for victim restitution. Transfer recorded with OP_RETURN 'claim:cryptorecoverytrust dot com'.
How much of the tracked exploit the white hats swept.
8 of 9 outlets skipped it: coinkite says updating firmware does not repair existing seeds.
10outlets compared
Same story, two versions
tap a side to read it in full
Cointelegraph
“About 40% of the Bitcoin associated with the second wave was swept by white hats to protect victims’ funds.”Read the original ↗
Altcoin Buzz
“The trust now holds roughly 2.8% of the exploit funds Galaxy is tracking.”Read the original ↗
One outlet frames by wave share, the other by tracked-total share.
52 BTC to Wyoming trust
White-hat operators moved 52.37 bitcoin tied to the July Coldcard hardware wallet exploit into an address associated with the Crypto Recovery Trust, according to Galaxy Digital head of research Alex Thorn. Thorn said the destination transaction carried an OP_RETURN message reading "claim:cryptorecoverytrust dot com" and that the transfer was recorded in Bitcoin block 967,948. Thorn described the 52.37 BTC as part of a sweep of Wave 2 cluster funds, and he said the amount represented 2.8% of the total tracked exploit funds.
“"Updating the firmware does not change or repair an existing seed."”
Thorn also said 3.0134 BTC included in the transfer came from addresses Galaxy had not previously tracked, while he said the origin of those coins remained unconfirmed. Coinkite’s advisory said, "Updating the firmware does not change or repair an existing seed."

Why seeds were guessable
Coinkite’s incident record described the Coldcard problem as a firmware seed-generation failure, where a firmware integration defect routed seed generation to MicroPython’s Yasmarang software pseudorandom generator instead of the device’s hardware random number generator. The vulnerability let attackers reconstruct wallet seeds offline, because the reduced randomness narrowed the range of possible private keys. Coinkite’s advisory said affected users must migrate to a new seed, and it said a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone.
Security researcher Nick Bax said he helped rescue about 50 bitcoin at the end of July because the funds were "imminently going to be stolen" due to the Coldcard entropy flaw. The Crypto Recovery Trust website process let potential victims enter their wallet addresses to determine whether the trust controls their funds.

Recovery totals still vary
TRM Labs said about 1,816 BTC remained in attacker wallets across four theft waves, while Galaxy Digital tracked a different total and said the 52.37 BTC transfer represented 2.8% of its tracked exploit funds. Cointelegraph reported that white hats secured about 40% of the Bitcoin moved in the Coldcard exploit’s second wave, transferring it to a Wyoming trust for victims. CGalaxy Digital head of research Alex Thorn cited a published total of 1,830 BTC across 9,162 addresses linked to the Coldcard vulnerability.
“About 1,816 BTC remains in attacker wallets across four theft waves.”
The Crypto Recovery Trust identified its legal entity as the Recovered Digital Asset Statutory Trust of Wyoming and named Agentic Trace LLC as trustee, while the trust said verified owners can submit claims and provide evidence for returned assets. The sources also said loss estimates vary depending on which attack waves, clusters, and recovery transactions are included, and Coinkite’s security status page does not publish a single definitive total for all stolen Bitcoin.