Some of the Bitcoin stolen in the sprawling Coldcard hardware wallet exploit is being routed toward a recovery effort, with white-hat actors moving funds into what they've labeled a trust for returning the coins.
According to Galaxy Research's blockchain monitoring, 40.71 BTC, worth about $3.31 million, was moved on Sept. 21 in a single transaction that consolidated coins tied to the exploit.
Myriad: How high will Bitcoin go? Click to make your prediction.
The transfer, spanning 11 addresses across 20 inputs and 480 outputs, carried an OP_RETURN message, a small note embedded in a Bitcoin transaction, reading "claims: cryptorecoverytrust.com." Galaxy attributed the coins to attackers it had tagged as "Footprint AA" and a second-wave hop from the hack.
In a related post, Galaxy's head of research Alex Thorn said a broader sweep pulled 52.37 BTC, drawn from several attacker clusters, into a fresh address flagged for the same Crypto Recovery Trust.
He noted the white-hatted funds represent roughly 2.8% of the total Coldcard exploit, a fraction of the haul that has otherwise remained largely dormant in attacker wallets.
The movement marks a notable turn in one of the year's largest self-custody disasters. The Coldcard exploit stemmed from a March 2021 firmware build error on Coinkite's Coldcard devices that generated seed phrases with far too little randomness, leaving private keys guessable. Because the flaw was baked into how the seed was created, updating the firmware couldn't fix a wallet already generated on a compromised device.
At its peak, the theft grew to roughly $130 million across thousands of addresses, with Galaxy tracking the sweeps as they unfolded in waves. Much of the stolen Bitcoin had sat untouched in attacker addresses for weeks, prompting speculation about whether any of it would ever move.
The appearance of a recovery-trust label suggests at least some parties are attempting to shepherd funds back to victims, though the specifics of how the Crypto Recovery Trust would operate, and how owners might claim their coins, weren't detailed in the on-chain messages.
Coinkite has previously urged exposed users to migrate to newly generated seeds and rolled out new security measures in the wake of the breach.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。