Crypto
Home›Crypto›Market Structure›Coldcard exploit Bitcoin routed to address labeled Cry…
Coldcard exploit Bitcoin routed to address labeled Crypto Recovery Trust
Galaxy Research says 40.7 BTC, about $3.31 million, was consolidated on Sept. 21 across 11 addresses with an on-chain message referencing cryptorecoverytrust.com.
White-hat actors have begun moving some of the Bitcoin stolen in the Coldcard hardware wallet exploit into an address they labeled as part of a Crypto Recovery Trust, Decrypt reported. Galaxy Research said the on-chain activity included an OP_RETURN message that referenced claims: cryptorecoverytrust.com.
According to Galaxy Research blockchain monitoring, 40.71 BTC, worth about $3.31 million, was moved on Sept. 21 in a single transaction that consolidated coins tied to the exploit across 11 addresses, using 20 inputs and 480 outputs. Galaxy attributed the funds to attackers it had tagged as Footprint AA, and also to a second-wave hop from the hack.
Galaxy said a broader sweep later pulled 52.37 BTC from several attacker clusters into a fresh address flagged for the same Crypto Recovery Trust. Alex Thorn, head of research at Galaxy, said the white-hatted funds represent roughly 2.8% of the total Coldcard exploit haul, with most of the remaining stolen Bitcoin still largely dormant in attacker wallets.
The Coldcard exploit traced back to a March 2021 firmware build error on Coinkite devices that produced seed phrases with too little randomness, making private keys guessable. Decrypt noted that because the flawed seed generation was baked into wallet creation, updating firmware could not fix already generated wallets, and theft at its peak reached about $130 million across thousands of addresses.
Latest closeBitcoin $85,554.46 ▼0.7%