A group of white-hat researchers has moved 52.37 BTC from wallets compromised in the COLDCARD exploit to a recovery address controlled by the Crypto Recovery Trust. Occurring around block 967,948, the transfer represents approximately 2.8% of the total funds drained during the attack.
The COLDCARD exploit resulted in attackers siphoning an estimated 1,500+ BTC, with total losses exceeding $100 million. Beginning on July 30, 2026, attackers drained approximately 594 BTC within minutes from exposed wallets using automated tooling and scripts to sweep vulnerable addresses in bulk.
Recovery Operation and Trust Structure
The effort was partly organized by the Digital Asset Recovery Trust (DART), which identified vulnerable address clusters linked to the COLDCARD entropy flaw. Researchers scanned for wallets still exposed to the vulnerability and secured recoverable funds ahead of malicious actors.
The consolidated transaction included an OP_RETURN message embedded directly into the Bitcoin blockchain, directing affected users to cryptorecoverytrust.com to file claims. DART had secured over 50 BTC by late July 2026, placing the funds into the Crypto Recovery Trust.
The trust is a Wyoming-based statutory entity advised by the international law firm Steptoe LLP. Its mission is to document recoveries, segregate assets from operational funds, and verify rightful ownership prior to release. The white-hat researchers did not seek bounties, and recovered funds are held separately to prevent commingling and establish a clear chain of custody.
Origin of the Firmware Vulnerability
The vulnerability stemmed from a firmware build error in specific COLDCARD hardware wallet models that compromised the device's hardware random-number generator. This component produces the entropy required for seed phrase generation. The resulting predictability allowed attackers to potentially reconstruct compromised seed phrases offline without network access.
Coinkite, the maker of COLDCARD, acknowledged the problem and issued emergency firmware updates. The build error reportedly originated in a March 2021 update, leaving certain wallets silently vulnerable for more than five years before the exploit took place.


