Coldcard firmware flaw and recovery trust efforts
Whiteāhat researchers, recovery organizations and a Wyoming statutory trust have converged around efforts to return Bitcoin tied to the Coldcard seedāgeneration flaw. Onāchain movements show 52.37 BTC was consolidated into an address associated with the Crypto Recovery Trust at Bitcoin block 967,948; the transaction included an OP_RETURN pointer directing affected owners to claim:cryptorecoverytrust.com so they can file ownership claims. Galaxy Digital researcher Alex Thorn tied the coins to Wave 2 clusters and footprints labeled AA, AU and AX and noted the amount represents roughly 2.8% of the exploit funds his team tracked; a transaction ID published alongside the analysis was also reported.
The underlying vulnerability traces to a firmware build integration error that, beginning with a March 2021 change, caused some Coldcard models to resolve seed generation to MicroPythonās Yasmarang pseudorandom generator rather than the intended hardware RNG. That reduced effective entropy made affected seed phrases searchable offline and enabled automated sweeping: an initial wave on July 30 drained about 594 BTC within minutes, while later tracking and independent investigations expanded the scope. Reported totals vary by dataset and wave, with estimates cited in the coverage ranging from roughly 1,500 BTC to about 1,830 BTC moved from thousands of addresses.
Coinkite published emergency firmware fixes (recommended releases include Mk4/Mk5 5.6.2 and Q 1.5.2Q) that prevent future weak seeds but cannot repair seeds already created under vulnerable firmware. The Digital Asset Recovery Trust (DART) and independent white hats conducted blockchain scans, secured funds thought recoverable, and by midāAugust had parked just over 50 BTC in the Crypto Recovery Trust. The Trust is structured to segregate recovered assets while ownership, sanctions and legal checks are completed; sources name Steptoe LLP advising the trustee and in other disclosures identify Agentic Trace LLC as the trustee entity. DART says researchers did not seek bounties and that recovered assets will be returned through a formal claims process, though competing claims, sanctions restrictions or criminal proceedings could change next steps. Affected users can query the Crypto Recovery Trust website to see whether the Trust controls funds tied to their wallet addresses and submit evidence to support a claim. Thorn did not immediately comment to some outlets, and reporting emphasizes that totals and cluster attributions differ across analyses.
This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.