AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsWhite Hats Beat Coldcard Hackers: 52 BTC moved to recovery trust
Crypto NewsBitcoin BTCTechnology

White Hats Beat Coldcard Hackers: 52 BTC moved to recovery trust

White hats moved 52.37 BTC tied to the Coldcard entropy flaw into a Wyoming recovery trust. About 1,816 BTC remains in attacker wallets across four theft waves.

AAnmol Billa•Sep 22, 2026
Pop-art comic cover: a masked white-hat figure holds up a Bitcoin coin stamped with the Coldcard logo next to a small trust shield, beside a speech bubble reading 52 BTC Recovered.
MentionedBTC$86,259.00-0.41%

White hats moved 52.37 Bitcoin tied to the Coldcard entropy flaw into an address controlled by the Crypto Recovery Trust, a Wyoming statutory trust, on Monday. The transfer was recorded in Bitcoin block 967,948 and carried an OP_RETURN message pointing to claim:cryptorecoverytrust.com, according to Galaxy Digital head of research Alex Thorn.

For a Coldcard holder, the question is whether their seed is one of the ones that can be guessed. The trust now holds roughly 2.8% of the exploit funds Galaxy is tracking. The rest, about 1,816 BTC according to TRM Labs, is still sitting in attacker-controlled addresses across four waves of theft that began on July 30, 2026.

What the bug actually is

The vulnerability is a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator. In plain terms: when a Coldcard created a new wallet, it was not generating keys from hardware randomness but from a software fallback seeded from the chip's unique ID and timer registers.

That fallback, called Yasmarang, produced a much smaller pool of possible seeds than a normal Bitcoin wallet. Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a standard 12-word BIP-39 seed. Block, the security firm that traced the fault, says an attacker who can determine or sufficiently constrain the device UID, timer state and prior RNG-call history can reproduce candidate output streams offline, without ever touching the device.

Who got drained and how fast

The first wave hit on July 30. An attacker drained 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million at the time. Roughly 594 BTC moved out of about 500 wallets into a single consolidation address within 25 minutes, according to TRM. Two more confirmed waves raised the observed total to 1,367.05 BTC across 4,585 addresses. TRM's wider tally, which counts a fourth wave, puts losses near 1,816 BTC (around $116 million) drained from more than 5,200 addresses.

Laundering has been limited so far: TRM notes a single 64.9 BTC Wasabi deposit and 200 ETH sent to Tornado Cash on August 4, 2026. Galaxy has reported roughly 600 suspected attacker-controlled addresses to federal investigators, compliance firms and cybersecurity investigators. TRM is not attributing the theft to a specific actor.

What the white hats did

Security researcher and SEAL 911 incident responder Nick Bax said on Sept. 9 that he helped rescue about 50 BTC at the end of July because the funds were "imminently going to be stolen" due to the Coldcard entropy flaw. DART, the Digital Asset Recovery Trust, reported that it and independent white-hat researchers had secured just over 50 BTC from vulnerable addresses as of Aug. 17, moving them before malicious actors could reach them.

The Crypto Recovery Trust is the Wyoming entity that received the 52.37 BTC. Its website identifies the legal entity as the Recovered Digital Asset Statutory Trust of Wyoming, with Agentic Trace LLC as trustee. Potential victims can enter their wallet addresses on the trust's website to determine whether the trust controls their funds.

What users should do

Coinkite's advisory is blunt: "Updating the firmware does not change or repair an existing seed." Affected users must migrate to a new seed, unless they qualify for the dice-entropy exception. Coinkite says a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone, and adds that funds controlled by seeds generated on affected firmware are at risk only if the seed was created without at least 50 independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase. TAPSIGNER, OPENDIME and SATSCARD use different codebases and are unaffected.

What firmware is current

The current recommended standard releases are Mk4/Mk5 5.6.2 and Q 1.5.2Q, both issued Sept. 3. Edge users are directed to 6.6.1X for Mk4/Mk5 and 6.6.1QX for Q. Vulnerable firmware versions include Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive, Mk4 and Mk5 before standard version 5.6.0 or Edge version 6.6.0X, and Q before standard version 1.5.0Q or Edge version 6.6.0QX.

What's still open

The exact split of the 52.37 BTC between the second wave and other waves is not public. Galaxy confirmed 3.0134 BTC came from addresses it had not previously tracked but did not break the rest down further. The various trackers (Galaxy, TRM and The Hacker News) cite different totals because they are using different cluster methods, and Coinkite has not published a single official loss figure. No one has attributed the attack to a named actor. The Crypto Recovery Trust has not said when it was established or whether any funds have been returned to verified claimants.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

Pop-art comic illustration of a large gavel striking a rolled CLARITY bill at center-right, a money bag labeled FAIR behind it, and Coinbase and Ripple logo badges at the lower right, beside a speech bubble reading CLARITY BLOCKED.
Regulation
Sep 22, 2026

Senate Blocks CLARITY Act as Crypto PAC Targets Brown

CLARITY Act failed a 49-50 Senate vote on Sept. 15. Fairshake plans to spend $30M opposing Sherrod Brown in Ohio, while a lame-duck revival remains possible.

XRP
Anmol Billa
Pop-art comic cover: the Altcoin Buzz logo sits top-left, a speech bubble on the left reads 'Europe's first Zcash ETP', and a coin badge bearing the 21Shares and Zcash marks stands on a sunburst on the right with a 2.5% fee tag beneath it.
PrivacyAltcoins
Sep 22, 2026

21Shares Launches Europe's first Zcash ETP at 2.5% fee

21Shares listed Europe's first Zcash ETP on Euronext Paris and Amsterdam, after Grayscale's ZCSH ETF debuted in the US. The product carries a 2.5% annual fee.

ZECETHFI
Bikash Deka
Pop-art illustration of a euro symbol locking down a stack of stablecoin coins, with a gavel and a red ban stamp over a yield badge.
StablecoinsRegulation
Sep 22, 2026

EU Central Banks Push to Extend Stablecoin Yield Ban to Lending and Staking

The ECB and EU national central banks want MiCA's stablecoin interest ban extended to crypto lending, staking and borrowing, citing risks of indirect yield

Anmol Billa