White-hat actors have initiated the recovery of Bitcoin linked to the extensive Coldcard hardware wallet exploit, moving millions in stolen funds toward a return process. The movement marks a significant development after months of inactivity in addresses connected to one of the largest self-custody security failures in recent years.
Recovery effort gathers pace
On September 21, blockchain analysis by Galaxy Research identified a transaction involving 40.71 BTC—worth approximately $3.31 million at the time—consolidated from addresses associated with the Coldcard exploit. The transaction included an OP_RETURN message, embedding the phrase “claims: cryptorecoverytrust.com” to signal its link to a recovery trust initiative. This specific transfer gathered funds from 11 different addresses using 20 inputs and distributing them through 480 outputs.
Galaxy attributed the transaction to groups it has labeled as “Footprint AA” and a second-wave of activity following the original Coldcard hack, highlighting the ongoing efforts by white-hat actors to reclaim assets for affected users.
In an update, Alex Thorn, head of research at Galaxy, stated the operation included a broader sweep that pulled 52.37 BTC from several clusters previously linked to attackers. These funds were similarly moved to a new address flagged for the Crypto Recovery Trust, further demonstrating coordination among those seeking to recover the lost Bitcoin.
Details of the Coldcard exploit
The Coldcard event arose from a significant firmware bug on Coinkite’s Coldcard hardware wallets in March 2021. The flaw created seed phrases with insufficient randomness, making the device-generated private keys vulnerable to brute-force attacks. This vulnerability affected all wallets generated on compromised devices, and users could not fix affected wallets simply by updating the firmware; new seed phrases were necessary to secure their assets.
As the exploit unfolded, Galaxy tracked that the wallet breach ultimately enabled attackers to steal Bitcoin across thousands of addresses, with total estimated losses reaching around $130 million. Despite the scale of the theft, much of the stolen cryptocurrency remained untouched in the attacker-controlled wallets, raising doubts about the recovery of any portion of these funds.
Mini dictionary: OP_RETURN, a script opcode in Bitcoin transactions used to embed small pieces of data on the blockchain, such as messages or claim information, without affecting the transfer of funds.
Scope of recovery and future uncertainties
Alex Thorn estimated that the recent white-hat recovery effort accounts for about 2.8% of the total amount stolen during the Coldcard exploit. Although a small proportion of the theft, this movement signals the first significant attempt to return funds to victims.
The transaction’s embedded references to the Crypto Recovery Trust suggest the creation of a dedicated vehicle for distributing recovered funds, but details about the trust’s operations or how former wallet owners might submit claims remain unclear. To date, neither the full mechanics of the recovery process nor its timeline have been shared through on-chain communications.
The recovery of even a small portion of assets is a noteworthy turn in an attack of this magnitude, especially given the length of time that most stolen funds have stayed dormant.
In response to the exploit, Coinkite, the Canadian company behind Coldcard, has advised impacted users to move their Bitcoin to wallets generated with new, uncompromised seeds and has implemented additional security protocols to protect future users.
| Event | BTC Amount | Value | % of Exploit | Date |
|---|---|---|---|---|
| White-hat transfer | 40.71 BTC | $3.31 million | 2.8% | Sept. 21 |
| Total exploit | Approx. 1,490 BTC (estimated) | $130 million (peak) | 100% | March 2021 onwards |




