White-hat operators involved in the Coldcard entropy exploit have consolidated 52.37 BTC into a fresh Bitcoin address tied to Crypto Recovery Trust, a Wyoming-based statutory trust set up to safeguard compromised digital assets and return them to their verified original owners.
The move was disclosed on September 21, 2026 by Alex Thorn, Head of Firmwide Research at Galaxy Research, and marks the first sizeable public on-chain delivery of the recovery cluster into a clearly labeled address.
According to Thorn’s thread on X, the coins were drawn from Wave 2 and from three tracked victim clusters that Galaxy Research labels as footprints AA, AU, and AX. They were consolidated into a new address in Bitcoin block 967,948, and the transaction included an OP_RETURN field, a Bitcoin script opcode that permits a small amount of arbitrary data to be stored on-chain, carrying the message “claim:cryptorecoverytrust dot com.”
Thorn estimated the white-hat portion at 2.8% of the published Coldcard exploit total. The consolidation transaction is viewable on mempool.space.
Thorn added that the funds “appear to be the coins that @bax1337 from @_SEAL_Org wrote about helping to secure 12 days ago,” referring to a September 9, 2026 post by Nick Bax, a security researcher affiliated with the Security Alliance (SEAL), a coordination group for on-chain security professionals.
Bax said that at the end of July, he had been involved in rescuing roughly 50 BTC that “were imminently going to be stolen due to the COLDCARD entropy flaw,” and that the funds had been placed with a Wyoming trust structured to return the coins to their rightful owners.
Bax pointed readers to an August 17, 2026 report by DART, a digital asset recovery organization, titled “Just Over 50 BTC Rescued During the ColdCard Entropy Crisis.” DART said independent white-hat researchers had identified vulnerable funded addresses and moved the coins before malicious operators could sweep them.
As of that report, DART’s internal ledger showed just over 50 BTC secured. Those coins were not held in a researcher’s personal wallet; they were deposited into Crypto Recovery Trust, described as a purpose-built Wyoming statutory trust whose stated purpose is to safeguard insecure virtual currency and return it to verified original owners where lawful. Attorneys from the national security practice at Steptoe LLP, a Washington, D.C.-based law firm, serve as counsel to the trustee.
What Galaxy Mapped in the Consolidation
Thorn’s thread, accompanied by a Galaxy Research chart, breaks the 52.37 BTC into several previously tracked groups. A Wave 2 slice of 30.19 BTC covered 352 of Wave 2’s 1,478 victim addresses, later held as 30.18 BTC after a second hop. Footprint AX contributed 17.98 BTC from 100 victim addresses, described as 100% white-hatted. Footprints AA and AU added 1.16 BTC and 0.03 BTC respectively, also described as 100% white-hatted.
An additional 3.0134 BTC entered the same Crypto Recovery Trust address in the same transaction. Thorn said Galaxy had not previously seen those coins. He treated them as a “source unestablished” input that was co-spent with confirmed white-hat Coldcard coins, and therefore likely recovered Coldcard funds, while stating that Galaxy still requires further evidence before promoting that attribution.
Thorn said the Wave 2 coins now sitting with the trust represent roughly 40% of that wave. The remaining 45.9 BTC, or 60% of Wave 2, is still held in other hands. He said he does not know whether that remainder is also white-hat activity.
He added that transaction shapes look similar and that he has spoken to victims whose addresses appear in both portions of Wave 2, which is why Galaxy continues to treat the full wave as Coldcard-related. He still described the remaining operator or operators as distinct from the cluster that delivered coins to Crypto Recovery Trust.
Where the Rest of the Exploit Still Sits
Using Waves 1, 2, and 3 plus the newly labeled Crypto Recovery Trust funds, Thorn put the accounted total at 1,393 BTC, or 76.1% of Galaxy’s published Coldcard exploit figure at the time of the thread. Wave 1 remains untouched at 1,082.57 BTC. Wave 2 is 40% white-hatted, with 45.9 BTC still untouched.
Wave 3 has 116.98 BTC untouched, about 55%, while 97.09 BTC has been passed through CoinJoin, a Bitcoin privacy technique that combines multiple transactions, or bridged to Ethereum through THORChain, a cross-chain liquidity protocol, including paths associated with Tornado Cash, an Ethereum-based mixing service. Footprints AX, AA, and AU are fully attributed to white-hat recovery in this mapping.
That Wave 3 cash-out track matches earlier Galaxy analysis, previously covered by The Crypto Times in Coldcard Hacker Moves 45% of Wave 3 Bitcoin via THORChain and CoinJoins on September 7, 2026, when Thorn reported that the Wave 3 operator had moved 97.09 BTC from the largest vaults in size order.
Galaxy’s most recent broad loss update, reported by The Crypto Times in Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses on August 24, placed high-confidence losses at 1,789.28 BTC across 8,865 addresses, worth approximately $114.7 million at the time of theft.
The September 21 thread is not a full restatement of that victim-loss tally; it is an accounting of which already tracked clusters have now been labeled white-hat and moved into the trust.
How Victims Can Check a Claim
Thorn advised Coldcard victims to search wallet addresses at the Crypto Recovery Trust portal, adding that he would also contact victim reporters whose coins appear on the input side of the consolidation. According to the trust’s site, claimants keep their private keys local, sign a one-time message in their wallet, and submit the signature along with supporting records. A tracking token is used to follow reviewer notes and any requests for additional evidence. The site also offers a public-address check tool, and does not publish a full wallet list or balances.
DART’s August 17 report described the legal process behind that front end: document the rescue, segregate the assets, run ownership and source-of-funds review, screen for sanctions, attempt notice to affected parties, and return coins only after verification. DART framed the structure as an owner-first custody path, not a bounty arrangement.
Background on the Coldcard Entropy Flaw
The underlying incident began on July 30, 2026, when attackers began sweeping funded Bitcoin addresses whose seeds had been generated on affected Coldcard firmware. Coldcard is a hardware wallet manufactured by Coinkite, a Canadian company.
Coinkite published a security advisory the same day, and later issued a technical backgrounder explaining that a firmware defect caused seed generation to fall back to a weak software pseudorandom number generator (PRNG) instead of the intended hardware random-number generator (RNG).
The result was seeds with far less entropy, the term for the randomness used to generate cryptographic keys, than the designed 128 bits. On affected Mk2 and Mk3 devices, the effective key space was commonly assessed at roughly 40 bits, while newer models were assessed at a higher but still reduced figure, often cited around 72 bits, according to a separate analysis by Block Engineering. Devices were not remotely seized. Attackers reconstructed candidate keys offline and spent from matching on-chain addresses.
Coinkite has said a firmware update does not repair a seed already created on affected software. Users must generate a new seed on fixed firmware and migrate funds. Additional protection cited across Coinkite, Chainalysis, and Galaxy Research guidance includes a strong unique BIP-39 passphrase, referring to Bitcoin Improvement Proposal 39, the standard for mnemonic seed phrases, sufficient independent dice rolls at seed creation, or a multi-signature setup in which the Coldcard key is only one signer.
The Crypto Times first reported the opening 594 BTC sweep on July 31, 2026 and has since tracked successive Galaxy Research updates, Wave 3 and Wave 4 activity, THORChain and Tornado Cash movement, law-enforcement leads from Block and Galaxy Research, and Coinkite’s later firmware releases.
The white-hat transfer does not reduce the still-untouched Wave 1 cluster of 1,082.57 BTC, and it does not resolve ownership for coins already mixed or bridged by other operators. It does, however, create a documented legal path for the 52.37 BTC now sitting under the Crypto Recovery Trust label, along with the 3.01 BTC co-spent into the same address.
Also Read: Circle Launches Bitcoin-Backed cirBTC on Arc for DeFi Use
