White-hat actors moved 2.8% of Coldcard exploit proceeds into a recovery trust address, signaling potential recovery efforts.
Security & Exploits ·
White-hat actors consolidated 52.37 BTC from multiple attacker clusters into an address labeled for a "Crypto Recovery Trust," representing 2.8% of the total Coldcard exploit haul. The movement occurred via a transaction embedding a message directing to cryptorecoverytrust.com, marking a potential recovery effort for stolen funds stemming from a March 2021 firmware flaw that compromised seed phrase generation. At its peak, the exploit totaled approximately $130 million across thousands of addresses, with most stolen Bitcoin remaining dormant in attacker wallets since the theft unfolded in waves. The specifics of how victims might claim recovered coins through the trust have not been detailed in on-chain messages.