White Hats Funnel Coldcard Exploit BTC to On-Chain ‘Recovery Trust,’ Signaled via OP_RETURN

White hats moved 40.71 BTC tied to the Coldcard exploit and flagged 52.37 BTC to a “Crypto Recovery Trust,” just 2.8% of the haul. OP_RETURN messages hint at restitution plans.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

September 22, 2026

A small but telling shift is underway in the Coldcard exploit saga: white-hat operators are corralling part of the stolen Bitcoin into a dedicated on-chain “Crypto Recovery Trust,” using OP_RETURN messages as the public signal of intent.

Here’s what actually moved. On September 21, 40.71 BTC—about $3.31 million—was swept in a single transaction consolidating exploit-linked coins. The transaction spanned 11 addresses with 20 inputs and 480 outputs and carried the OP_RETURN note: “claims: cryptorecoverytrust.com.” Separately, a broader sweep consolidated 52.37 BTC into a fresh address in block 967,948. That transaction included an OP_RETURN reading “claim:cryptorecoverytrust dot com” and drew from attacker clusters previously labeled Wave 2, Footprints AA, AU, and AX. In aggregate, those white-hatted funds amount to roughly 2.8% of the total Coldcard exploit.

The attack itself traces back to a March 2021 firmware build flaw on Coinkite’s Coldcard devices that produced seed phrases with insufficient entropy. Because the weakness sat in the seed generation step, a later firmware update couldn’t salvage wallets already derived on compromised devices. The theft ultimately touched thousands of addresses and peaked around $130 million, with many outputs sitting dormant for weeks.

The interesting part isn’t the size—2.8% is marginal—but the method. Using OP_RETURN as a coordination rail to advertise a restitution process is clever for signaling, yet it is not binding. The chain can broadcast an intent, not a governance framework. For this “Crypto Recovery Trust” to deliver credibly at scale, a few design choices matter: - Claims need cryptographic proofs (e.g., signed messages from original addresses or deterministic derivation paths) to prevent opportunistic false filings. - Custody setup should be transparent and minimally trusted—think multisig with auditable policies, deterministic distribution logic, and timelocks to reduce single-actor risk. - Communication must be unambiguous. The on-chain notes used slightly different strings (“claims: cryptorecoverytrust.com” versus “claim:cryptorecoverytrust dot com”), which could confuse victims and invite spoofing. - Ethical guardrails matter. While many view white-hat interception as restitution-driven, it still involves seizing assets to return them. Clear documentation, auditability, and a defined claims hierarchy can mitigate disputes.

Why move now? Behaviorally, attackers appear content to let tainted UTXOs lie fallow, which creates a window for counter-parties who can reliably derive seeds affected by the flaw to preempt further theft and stage returns. Market context may also play a role: around the time of these transactions, Bitcoin traded near $86,203, up roughly 13% on the day, with a 24-hour range of $85,107 to $87,330 (per CoinGecko). Prediction markets like Myriad were showing about a 52% chance BTC would sit above $86,000 both this week and this month—conditions that can nudge liquidity decisions without changing the underlying on-chain calculus.

For impacted users, the practical next step remains unchanged: migrate to a newly generated seed created on a fixed device and treat any prior wallet as compromised. Coinkite has been urging that move since disclosure and has rolled out additional security measures. For the recovery effort, success will hinge less on memos in OP_RETURN and more on whether the trust publishes a rigorous, verifiable, and survivor-friendly claims process—and whether further sweeps can expand that 2.8% into something more meaningful.

Until then, block 967,948 and the 40.71 BTC consolidation are useful breadcrumbs: evidence that restitution via on-chain coordination is possible, but not yet a closure for thousands of affected addresses.