White-hat team launches Bitcoin recovery operation related to Coldcard hardware wallet vulnerability
White-hat hackers have launched recovery efforts against bitcoins associated with a large-scale Coldcard hardware wallet vulnerability and are directing millions of stolen funds into the return process. The move marks a major development in connecting addresses linked to the most serious self-managed security failure in recent years after months of silence.
Recovery efforts accelerate
On September 21, Galaxy Research's blockchain analysis revealed that a transaction involving 40.71 BTC (valued at approximately US$3.31 million at the time) occurred, and the funds were merged from addresses linked to the Coldcard vulnerability. The transaction contains an OP_RETURN message embedded with the words "claims: cryptorecoverytrust.com" to indicate its association with a recycling trust plan. This specific transfer collects funds from 11 different addresses through 20 inputs and distributes them through 480 outputs.
Galaxy attributed the transaction to a group it labeled as "Footprint AA" and a second wave of activity following the original Coldcard hack, highlighting the white-hats 'continued efforts to regain the assets of affected users.
In the latest status update, Galaxy research director Alex Thorn said the operation included a broader sweep that extracted 52.37 BTC from several clusters previously associated with the attacker. The funds were also transferred to a new address labeled Crypto Recovery Trust, further evidence of the coordination between those seeking to recover lost bitcoins.
Coldcard vulnerability details
Coldcard事件源于Coinkite公司的Coldcard硬件钱包在2021年3月出现的一个严重固件错误。该缺陷导致生成的助记词随机性不足,使得设备生成的私钥容易受到暴力破解攻击的影响。此漏洞影响了所有在受损设备上生成的钱包,用户仅通过更新固件无法修复受影响的钱包;必须使用新的助记词才能确保资产安全。
随着漏洞的展开,Galaxy追踪发现,这次钱包泄露最终使攻击者能够从数千个地址中窃取比特币,估计总损失达到约1.3亿美元。尽管盗窃规模巨大,但大部分被盗加密货币仍停留在攻击者控制的钱包中未动,这引发了人们对能否追回部分资金的怀疑。
微型词典:OP_RETURN是比特币交易中用于在区块链上嵌入少量数据(如消息或声明信息)而不影响资金转移的脚本操作码。
回收范围与未来的不确定性
Alex Thorn估计,最近的白帽回收行动约占Coldcard漏洞事件中被盗总额度的2.8%。虽然这只是盗窃的一小部分,但这一举动标志着首次有重大尝试将资金返还给受害者。
交易中嵌入的对Crypto Recovery Trust的引用表明,正在创建一个专门的载体来分发回收的资金,但该信托的运作细节或前钱包所有者如何提交索赔仍不清楚。迄今为止,尚未通过链上通信分享回收流程的全部机制或其时间表。
考虑到大多数被盗资金长期处于休眠状态,即使是少量资产的回收也是这场大规模攻击中的一个值得注意的转变。
作为对漏洞事件的回应,加拿大公司Coinkite(Coldcard背后的公司)建议受影响用户将其比特币转移到使用全新、未受损助记词生成的钱包中,并实施了额外的安全协议以保护未来用户。

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC