White-hat actors have moved 40.71 BTC, valued at approximately $3.31 million, from the Coldcard exploit into what they labeled a recovery trust on September 21. The transfer included an embedded message referencing "cryptorecoverytrust.com."
According to Galaxy Research's blockchain analysis, the transaction consolidated coins from multiple attacker addresses across 11 addresses, with 20 inputs and 480 outputs. Galaxy attributed the funds to attacker clusters labeled "Footprint AA" and a second-wave hop from the exploit.
A broader consolidation pulled an additional 52.37 BTC from several attacker clusters into a fresh address flagged for the same recovery trust, representing roughly 2.8% of the total Coldcard exploit funds.
The Coldcard Vulnerability
The Coldcard exploit stems from a March 2021 firmware flaw in Coinkite's hardware wallet devices. The error generated seed phrases with insufficient randomness, making private keys guessable. Because the flaw affected how seeds were initially created, firmware updates could not fix wallets already generated on compromised devices.
At its peak, the theft reached approximately $130 million across thousands of addresses. Most of the stolen Bitcoin remained dormant in attacker wallets for weeks following the exploit.
Recovery Effort
The movement of funds into a labeled recovery trust suggests an effort to return coins to victims, though the specifics of how victims might claim their funds were not detailed in the on-chain messages.
Coinkite has advised exposed users to migrate to newly generated seeds and implemented additional security measures following the breach.


