Overview
- White-hat researchers consolidated 52.37 BTC into an address controlled by the Crypto Recovery Trust Tuesday and included an OP_RETURN message that directs affected users to cryptorecoverytrust.com to file claims.
- Galaxy Digital’s analysis ties the funds to Wave 2 exploit clusters and estimates the transfer equals about 2.8% of the tracked Coldcard thefts, with part of Wave 2 now identified as white-hat recoveries.
- Investigators say the thefts began after a March 2021 firmware regression caused Coldcard devices to fall back to MicroPython’s Yasmarang software PRNG, producing weakened seeds that attackers could reconstruct offline.
- Estimates of total losses range around 1,500–1,800+ BTC and forensic teams report some stolen coins are still being laundered through services such as THORChain swaps and CoinJoin, prompting continued exchange and law-enforcement monitoring.
- The Crypto Recovery Trust is a Wyoming statutory trust with Agentic Trace LLC named as trustee and legal advice from Steptoe LLP; recovered coins are segregated for ownership checks and claims, and Coinkite’s firmware patches cannot secure seeds already generated so exposed users must create new seeds and move funds.