Security researchers transferred 52.37 BTC, valued at about US$ 4.5 million, which had been withdrawn preventively from wallets exposed to the Coldcard vulnerability to a trust created to return the assets to their owners. The movement was identified by Alex Thorn, head of research at Galaxy Digital, and disclosed on Monday (21).
The bitcoins were consolidated into a new address associated with Crypto Recovery Trust, an entity registered in Wyoming. The transaction, confirmed in block 967,948 of the Bitcoin network, included an OP_RETURN message directing potential victims to the trust's website to begin the recovery process.
According to Galaxy's tracking, the 52.37 BTC represent about 2.8% of the funds linked to the exploit that the company tracks. In the second wave of movements identified during the incident, approximately 40% of the bitcoins were withdrawn by whitehats before they could be reached by those responsible for the attack.
Part of the amount came from groups of addresses already classified by Galaxy as related to the incident. Another 3.0134 BTC included in the transfer had not been previously tracked and probably also correspond to recovered funds, although the origin has not yet been confirmed.
Coldcard flaw weakened seed generation
The incident began in late July after the discovery of a flaw in the firmware of the Coldcard, a physical Bitcoin wallet produced by Coinkite. An integration error caused certain versions to use a software pseudorandom generator in the seed creation process, instead of relying exclusively on the hardware random generator intended by the project.
With less entropy, some seeds ended up with a significantly smaller search space. This allowed attackers to reconstruct private keys offline and move bitcoins without needing to gain remote access to the devices. In August, Galaxy estimated confirmed losses of at least 1,778.84 BTC, then equivalent to US$ 112.7 million, across more than 8,600 addresses.
Coinkite has already released corrected versions of the firmware, but the update does not fix seeds previously created with vulnerable versions. Affected users need to generate a new seed on corrected firmware and transfer their funds to new addresses.
The Crypto Recovery Trust says it was created to keep recovered digital assets separate while it verifies ownership before returning them. Victims can consult the recovery service and submit evidence to request the recovered bitcoins.



