Coldcard exploit: 2.8% of stolen BTC routed to recovery trust
On-chain records show 52.37 BTC moved into a flagged address with an OP_RETURN claim, a small fraction of the $130 million theft.
Yuna · Sep 23, 2026 · 2 min
Galaxy Research identified a significant consolidation of Bitcoin linked to the Coldcard hardware wallet exploit, with a portion of the assets directed toward a recovery initiative. This activity marks a departure from the prolonged dormancy of the stolen funds, signaling that actors are now attempting to organize the haul rather than simply holding it.
According to Galaxy, white-hat actors executed a single transaction on Sept. 21 moving 40.71 BTC, valued at approximately $3.31 million. The transaction was complex, spanning 11 addresses while utilizing 20 inputs and 480 outputs to gather coins associated with the exploit. Galaxy attributed these funds to attackers tagged as "Footprint AA" and a second-wave hop from the hack.
The consolidation appeared in block 967,948, accompanied by an OP_RETURN message reading "claim:cryptorecoverytrust dot com." Alex Thorn, head of research at Galaxy, noted that "a broader sweep pulled 52.37 BTC from several attacker clusters into a fresh address flagged for the same trust" per Galaxy Research. These funds represent roughly 2.8% of the total Coldcard exploit.
The underlying theft peaked at roughly $130 million, stemming from a March 2021 firmware build error that left seed phrases guessable. The Hacker News reported an earlier wave where an attacker drained 1,196 addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million. Decrypt noted that "the appearance of a recovery-trust label suggests at least some parties are attempting to shepherd funds back to victims." Per the Federal Reserve, the next rate decision is on October 28, 2026. The Bureau of Labor Statistics scheduled the next CPI release for October 14, 2026.
A critical friction point remains in the operational mechanics of the recovery. The OP_RETURN label indicates an intent to facilitate a return of funds to victims, yet the on-chain data does not reconcile the existence of a trust with a functional claim process. The message identifies a destination, but it provides no mechanism for owners to validate their identity or retrieve their coins. Until that operational gap is bridged, the on-chain movement defines a direction for the funds, not a completed restitution.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.