Coin Brief ENDE

Whitehats move 52 BTC from the Coldcard seed flaw into a recovery trust

Operators described as whitehats have moved 52.37 BTC connected to July's Coldcard hardware wallet exploit into an address associated with a newly formed recovery trust, according to Galaxy Digital's head of research Alex Thorn, reported by CoinDesk on 22 September 2026. The receiving address carries an OP_RETURN message pointing at a recovery-trust domain.

The underlying failure is a seed generation flaw. Beginning 30 July, in multiple waves, affected wallets generated seeds using a weaker software-based random source instead of the device's dedicated random number generator, which left some seeds reconstructable by an attacker. Reported losses run past $100 million in bitcoin. Coinkite, which makes Coldcard, has patched the firmware.

One consequence is stated plainly in the reporting and deserves repeating: funds already exposed under the old seeds remain at risk regardless of the patch.

Whitehats move 52 BTC from the Coldcard seed flaw into a recovery trust
Whitehats move 52 BTC from the Coldcard seed flaw into a recovery trust — Coin Brief

What it means

A firmware fix stops new bad seeds. It cannot un-generate an old one. Any wallet whose seed was produced by the defective path is permanently compromised in the sense that matters — the secret was drawn from a space an attacker can search — and the only remedy is to move the funds to keys generated correctly.

The OP_RETURN pointer is a notable move in its own right: publishing the claim route on chain, attached to the transaction that holds the funds, makes the recovery path verifiable by anyone holding a block explorer instead of depending on an announcement that could be impersonated. It also, unavoidably, creates a target for phishing that mimics it, and an on-chain message proves the message's placement, not the honesty of whoever placed it.

We have not independently verified the addresses, the trust, or the attribution, all of which rest on the cited research. ⚠️ Nothing here is a recommendation to interact with any address or service, and anyone affected should verify a recovery route through the wallet vendor's own channels before acting.

Written by Victoria Shinder.