Thursday, September 24, 2026

Coldcard users can now verify whether any of their funds were reclaimed by white‑hat researchers. Galaxy analyst Alex Thorn identified a September 21 Bitcoin transaction that carries a Crypto Recovery Trust claim reference, linking it to approximately 52.37 BTC moved from wallets associated with the Coldcard exploit.

Thorn advised owners to look up their public Bitcoin addresses on the trust’s website. A matching address can initiate an ownership claim; any potential payout will be subject to verification. Importantly, the check requires only a public address—never a seed phrase or private key.

Mempool’s status record confirmed the transaction in block 967,948. In his September 21 tracing report, Thorn noted that this sum represents roughly 2.8 % of the exploit funds that Galaxy has been monitoring.

Thorn also observed an additional 3.0134 BTC flowing into the destination from addresses that Galaxy had not previously monitored. He suggested these could be further white‑hat recoveries, although their connection to Coldcard remains unconfirmed.

In an August 17 report, the digital‑asset recovery firm DART said that it, together with independent researchers, had secured just over 50 BTC, according to its internal ledger, and had deposited the recovered bitcoin into the Crypto Recovery Trust.

The September 21 transaction provides a public audit trail for the recovery that DART had disclosed a month earlier.

What happens after a Bitcoin address match?

DART explains that its trust process verifies recovery records, chain of custody, and proof of ownership—including source‑of‑funds and exchange documentation. Sanctions, competing claims, or other restrictions may influence whether any funds are ultimately returned.

A public Bitcoin trace linked 52.37 BTC to Coldcard’s recovery disclosure, but ownership verification and victim payouts remain unresolved.

The Coldcard entropy flaw has made certain older wallet seeds easier to reconstruct. DART notes that a seed generated with the vulnerable firmware remains exposed even after a firmware update, and users whose funds are at risk should follow the manufacturer’s migration recommendations.

DART also cautions against submitting seeds, private keys, PINs, or recovery codes via any web form. The initial address check Thorn described requires only a public address; establishing ownership is a separate step.

Source link

Exit mobile version