Invest1 publisher2 min readPublished
White hats move 52.37 BTC into a Wyoming statutory trust built for COLDCARD victims
The Crypto Recovery Trust, a Wyoming entity advised by Steptoe LLP, now controls coins worth about $3.5m at the exploit's implied price, against more than $100m that COLDCARD holders lost from July 30, 2026.
The Investor · Invest desk

What happened
- White-hat researchers moved 52.37 BTC out of wallets compromised in the COLDCARD exploit and into a recovery address controlled by the Crypto Recovery Trust.
- The Crypto Recovery Trust is a Wyoming statutory entity advised by Steptoe LLP, and says it will verify rightful ownership before releasing anything to claimants.
- Coinkite acknowledged the flaw and shipped emergency firmware, and the build error behind it reportedly originated in a March 2021 update.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction The recovery rate depends on which of the source's own figures holds: 2.8% implies about 1,870 BTC was taken, while the stated 1,500-plus BTC estimate makes the same 52.37 BTC worth 3.5% of the loss.
- constraint Because the flawed entropy let anyone rebuild a victim's seed offline, the trust cannot treat a signature from a drained address as proof of ownership, and every claim needs evidence from outside the wallet.
- cost Even if every coin in the trust reaches a verified owner, holders are left carrying roughly $96.5m of the loss at the price implied by the reported figures.
- precedent A statutory trust with outside counsel, segregated assets and an on-chain pointer to a claims site is cheap to replicate, and becomes the default answer the next vendor reaches for after a firmware failure.
DART had reportedly secured more than 50 BTC by late July 2026 and parked it in the Crypto Recovery Trust [9]. The consolidated transfer is 52.37 BTC [1]. The gap between those two numbers is at most about 2.4 coins [5], so what settled around block 967,948 [2] is a change of custody on bitcoin white hats had already swept.
The sweep was fast. Attackers took roughly 594 BTC within minutes of July 30, 2026 [4], about 40% of the 1,500-plus BTC estimated for the whole exploit [3]. That speed pointed to scripts scanning the chain for addresses built from the faulty entropy and emptying them in bulk [5]. The researchers reaching the still-exposed wallets [7] were working in the same week [9].
Calling 52.37 BTC roughly 2.8% of the total drained [2] implies about 1,870 BTC left those wallets, while dividing it into the stated 1,500-plus BTC gives 3.5% [1]. Take the loss figure of more than $100 million over 1,500 coins and the implied price is about $66,700 each, which values the pool near $3.5m [2]. Around 1,448 BTC is somewhere else [4].
Verification is the expensive part. The trust says it will document recoveries, keep the assets segregated from operational funds, and confirm rightful ownership before releasing anything [11], and the funds are held separately to establish a chain of custody for eventual disbursement [13]. But the firmware build error compromised the hardware random number generator that produced seed entropy [14]. That predictability let a seed be reconstructed offline, with no network access and no infrastructure [15]. Signing a message from a drained address does not separate the owner from whoever rebuilt the same seed. Claims have to rest on something outside the wallet. The report does not say whether any victim has been paid, or who pays for Steptoe LLP's advice [10].
The copyable part of this is the paperwork: a Wyoming statutory entity with outside counsel and segregated assets. The consolidating transaction also carries an OP_RETURN message pointing holders at cryptorecoverytrust.com to file [8]. It cost the researchers their time and nothing else, since none of them asked for a bounty [12]. I would expect the next hardware-wallet failure to be routed through the same shape, and the test is simple: if the 52.37 BTC is still unallocated in a year, this was an escrow address with a website. The build error reportedly shipped in a March 2021 update, roughly five years and four months before the drain [17][6], and Coinkite acknowledged the issue and released emergency firmware [16].
What to watch
- Whether further tranches of the missing 1,448 BTC reach the Crypto Recovery Trust's recovery address, which would move the stated 2.8% share.
- Whether Coinkite's involvement extends beyond the emergency firmware to funding the trust's operations or contesting claims.
- Whether the trust names a trustee and publishes the ownership evidence it will accept from claimants.