White-hat researchers transfer 52 BTC from COLDCARD exploit to recovery trust

Editorial illustration: A white-gloved hand lowers a stack of copper-colored coins into an open blue box with a shield emblem beside a cracked electronic wallet with exposed circuitry.

In brief

  • White-hat researchers moved 52.37 BTC from COLDCARD-compromised wallets to Crypto Recovery Trust for victim reimbursement.
  • COLDCARD exploit drained 1,500+ BTC since July 30, 2026, with total losses exceeding $100 million.
  • Vulnerability originated in March 2021 firmware build error affecting certain COLDCARD hardware wallet models.
  • Crypto Recovery Trust is a Wyoming-based statutory entity advised by law firm Steptoe LLP.

The Exploit and Its Scale

The COLDCARD vulnerability traces back to a firmware build error in certain hardware wallet models that compromised the device's random-number generator. The flaw reportedly originated in a March 2021 update, meaning some wallets had been silently vulnerable for over five years before attackers exploited them.

Starting on July 30, 2026, attackers drained approximately 594 BTC within minutes from exposed wallets. The broader attack saw an estimated 1,500+ BTC siphoned off, with total losses surpassing $100 million. Coinkite, the company behind COLDCARD, acknowledged the issue and released emergency firmware updates.

Recovery and Restitution

The Digital Asset Recovery Trust (DART) identified vulnerable address clusters tied to the COLDCARD entropy flaw and coordinated the recovery effort. DART had reportedly secured over 50 BTC by late July 2026, parking it in the Crypto Recovery Trust.

The recovered amount represents roughly 2.8% of the total funds drained during the attack. The consolidated transaction included an OP_RETURN message directing affected users to cryptorecoverytrust.com to file claims.

"A group of white-hat researchers has moved 52.37 BTC from wallets compromised in the COLDCARD exploit to a recovery address controlled by the Crypto Recovery Trust." — Crypto Briefing

What distinguishes this recovery is the researchers' motivation. The white-hat researchers involved did not seek bounties for their work, underscoring a commitment to victim restitution over personal gain. The Crypto Recovery Trust's structure—keeping recovered funds separate to establish a clear chain of custody—reflects a deliberate approach to eventual disbursement.

The COLDCARD incident illustrates both the risks inherent in hardware wallet supply chains and the potential for organized recovery when white-hat researchers step in.