White-Hat Hackers Route Coldcard Exploit Bitcoin Into 'Recovery Trust'
White-hat actors have consolidated a portion of Bitcoin linked to the 2021 Coldcard hardware wallet exploit into an address tagged for a 'Crypto Recovery Trust,' blockchain monitoring firm Galaxy Research reported. The transfer included about 40.71 BTC in a single Sept. 21 transaction, with a broader consolidation totaling 52.37 BTC—roughly 2.8% of the overall stolen funds Galaxy tracked.

Why It Matters
The move signals an organized effort to centralize some of the exploited funds for potential return to victims after a long period of dormancy, changing the dynamics of one of the largest self-custody breaches tracked this year. It also highlights on-chain methods—like OP_RETURN messages—for signaling intent in recovery attempts.
Key Facts
- amount-moved-single-transaction: 40.71 BTC (~$3.31 million)
- broader-consolidation-amount: 52.37 BTC
- percentage-of-total-exploit: Approximately 2.8% of the Coldcard exploit
- date-of-move: September 21, 2026
- on-chain-message: OP_RETURN reading 'claims: cryptorecoverytrust.com' (or similar)
Blockchain monitors at Galaxy Research identified a Sept. 21 transaction that moved 40.71 BTC tied to the Coldcard hardware wallet exploit into an address carrying a 'crypto recovery trust' note. The single transfer consolidated coins from multiple attacker-linked addresses and included an OP_RETURN field pointing to a Crypto Recovery Trust claim. Galaxy attributed the inputs to clusters it had previously labeled, including 'Footprint AA' and a second-wave hop from the hack.
In a follow-up post, Galaxy's head of research Alex Thorn said an expanded sweep drew 52.37 BTC from several attacker clusters into a newly created address flagged for the same trust. He estimated those coins make up about 2.8% of the total haul connected to the Coldcard breach, with the remainder of stolen funds largely remaining in attacker-controlled wallets.
The Coldcard incident traces back to a March 2021 firmware flaw in Coinkite's Coldcard devices that produced seed phrases with insufficient randomness, allowing private keys to be guessed for affected wallets. At its peak, blockchain trackers pegged the theft at roughly $130 million spread across thousands of addresses, with attackers moving coins in multiple waves. Much of that stolen Bitcoin had been dormant for weeks prior to the recent consolidations, prompting questions about whether any portion would ever be shifted.
The use of an on-chain OP_RETURN message identifying a recovery trust suggests some parties are attempting to centralize and possibly repatriate part of the stolen funds, but the posts and on-chain data do not explain how the Crypto Recovery Trust would function or how victims might claim coins. Coinkite has previously advised users exposed by the flaw to migrate to newly generated seeds and implemented additional security measures after the breach.
Keep Reading

Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

Cardano joins Solana, XRP Ledger in race to power AI agent payments

Dogecoin leads market rebound with 15% pump, bitcoin steady above $85,000
