White-hat actors have begun routing stolen Bitcoin from the massive Coldcard hardware wallet exploit into a designated recovery effort. On September 21, a single transaction moved 40.71 BTC, valued at approximately $3.31 million, consolidating coins linked to the breach. This transfer, which spanned 11 addresses across 20 inputs and 480 outputs, included an OP_RETURN message reading "claims: cryptorecoverytrust.com." Galaxy Research attributed these specific funds to attacker clusters tagged as "Footprint AA" and a second-wave hop.

In a broader sweep, Galaxy’s head of research Alex Thorn reported that 52.37 BTC were pulled from several attacker clusters into a fresh address flagged for the same Crypto Recovery Trust. These white-hatted funds represent roughly 2.8% of the total Coldcard exploit, which peaked around $130 million. The underlying vulnerability stemmed from a March 2021 firmware flaw on Coinkite devices that generated seed phrases with insufficient randomness, making private keys guessable. While much of the stolen Bitcoin had remained dormant in attacker wallets, this movement marks a notable shift toward potential restitution, though operational details of the trust remain unspecified.