The short version
- 52.37 BTC from the Coldcard firmware exploit landed in a Wyoming recovery trust on September 22, 2026, confirmed in block 967,948.
- Galaxy Digital's Alex Thorn flagged the transfer; the coins appear linked to a whitehat rescue by Nick Bax of SEAL Org in late July 2026.
- The recovered amount equals roughly 2.8 percent of Galaxy's tracked total of 1,829.28 BTC stolen across 8,865 addresses.
- The exploit stemmed from a firmware bug that used a software random number generator instead of the device's hardware chip, producing guessable wallet seeds.
52.37 BTC Confirmed on the Blockchain
On September 22, 2026, a transaction confirmed in Bitcoin block 967,948 moved 52.37 BTC from addresses linked to the Coldcard hardware-wallet firmware exploit to a new receiving address. The receiving address carries an OP_RETURN message — a type of output permanently written into the Bitcoin blockchain that cannot hold funds but can attach a short public note to any confirmed transaction.
Alex Thorn, Head of Firmwide Research at Galaxy Research — a division of Galaxy Digital — flagged the movement in a public post. Thorn noted that the moved coins appear to be the same batch that security researcher Nick Bax, known online as @bax1337 and working with SEAL Org, described securing at the end of July 2026. Galaxy Digital has tracked the Coldcard exploit since publishing its August 24 report.
The 52.37 BTC equals roughly 2.8 percent of the 1,829.28 BTC that Galaxy Digital tracked across 8,865 addresses connected to the July exploit. Galaxy's August 24 report valued the total stolen amount at approximately $114.7 million at the time of theft. That 2.8 percent share is measured against Galaxy's own tracked figure, not an official count from Coinkite, TRM Labs, or any court proceeding.
Check Bitcoin’s current reference price
A Firmware Bug That Made Seeds Guessable
The Coldcard exploit started on July 30, 2026. Coldcard is a physical Bitcoin wallet device made by Coinkite and sold as a high-security way to store private keys offline. The affected firmware build contained a critical flaw: when generating a new wallet seed, the device fell back to a software math routine instead of the dedicated hardware chip designed to produce truly random numbers.
A hardware random number generator draws from physical signals inside the chip — electrical noise and other unpredictable inputs — that no outsider can observe or replicate. The Coldcard firmware instead used MicroPython's software pseudo-random number generator, which runs a mathematical algorithm. An attacker who knows the algorithm and its starting value can reproduce every number the device produced and calculate the private key for any wallet it created.
Coinkite released a firmware patch after the exploit became public. The patch closes the software-PRNG fallback for new wallets, but any seed already created under the flawed build remains permanently exposed. Owners of affected wallets must generate a fresh seed on a patched device and move their coins to the new address — a step with real urgency because attackers already ran the same seed-guessing calculation months ago.
Learn how Bitcoin’s market price is formed
SEAL Org Swept Vulnerable Coins Before Attackers Could
SEAL Org is a nonprofit group of cryptocurrency security researchers whose goal is returning stolen digital assets to rightful owners. At the end of July 2026, researcher Nick Bax described securing roughly 50 BTC from wallet addresses that the firmware flaw had exposed. Bax's public account is consistent with Thorn's later attribution linking the coins now held in the Wyoming recovery trust to that same early intervention.
Thorn's exact wording matters: he wrote that the moved coins "appear to be" the batch Bax secured. That hedge signals an analyst's inference drawn from on-chain address patterns, not a confirmed chain-of-custody record. The Bitcoin blockchain makes every transaction public, but connecting a specific set of coins to a specific actor requires analyzing patterns across thousands of addresses, and different analysts can reach different conclusions from the same raw data.
When a security researcher sweeps vulnerable coins before a thief can, speed determines the outcome. The researcher broadcasts a transaction and whichever one confirms first wins. The bitcoin fees paid affect priority: a higher fee pushes a transaction toward the top of the queue, giving it a better chance of confirming before any competing sweep the attacker may have already broadcast to the network.
Compare the wider Bitcoin and crypto market
Inside the Wyoming Statutory Trust
Reporting from CoinDesk and CryptoTimes confirmed the receiving entity is a Wyoming statutory trust. Wyoming state law created a framework allowing trusts to hold digital assets, appoint a trustee, and run a formal claims process. Steptoe LLP's national security practice, based in Washington, D.C., is serving as legal counsel for the trust, according to CryptoTimes. Wyoming's trust statutes have attracted multiple crypto-custody arrangements since the state enacted digital-asset legislation.
One secondary aggregator reported Agentic Trace LLC as the trustee, but that detail appeared in only a single source and was not confirmed against a primary state filing, a court record, or a direct statement from the trust. Until the trustee's identity is confirmed by a primary document, the name should be treated as provisional. The trust's claims website, referenced in the on-chain OP_RETURN message, is where victims are directed to begin a recovery application.
A claimant who lost bitcoin in the exploit must prove ownership of an affected private key without actually moving the coins, which would alert any attacker still watching the blockchain. The standard method is a cryptographic signed message — a short text signed by the private key, proving control of that address without broadcasting a transaction. Bitcoin regulation at the federal level has not yet defined a standard procedure for theft claims filed with a statutory trust.
- Entity type: Wyoming statutory trust for digital assets
- Legal counsel: Steptoe LLP national security practice, Washington, D.C. (per CryptoTimes)
- On-chain pointer: OP_RETURN message in block 967,948 references the claims website
- Trustee: Agentic Trace LLC named by one secondary aggregator; not confirmed by any primary filing
- Transfer date: September 22, 2026, Bitcoin mainnet
Convert a Bitcoin amount using a reference rate
One Recovery Trust Cannot Cover Most of the Stolen BTC
Galaxy Digital's August 24 report tracked 1,829.28 BTC across 8,865 addresses as the full scope of the exploit. The 52.37 BTC moved to the recovery trust on September 22 leaves approximately 1,776 BTC still unaccounted for under Galaxy's tracking. TRM Labs, a separate blockchain analytics firm, estimated independently that roughly 1,816 BTC remained in attacker-controlled addresses — a figure that reflects slightly different address-clustering assumptions than Galaxy used.
The gap between the two estimates — Galaxy's accounting implying about 1,776 BTC unrecovered versus TRM Labs' figure of roughly 1,816 BTC still in attacker hands — shows how blockchain analytics firms can reach different totals from the same on-chain data. Each firm uses its own clustering algorithms and assumptions about which addresses belong to the same actor. Neither figure carries the authority of a court determination or a law-enforcement seizure order.
Bitcoin's hard cap on total supply means every recovered coin is genuinely scarce, and for affected holders, even partial recovery carries real value. The 52.37 BTC moved to the Wyoming trust on September 22 is the first publicly documented transfer of Coldcard exploit funds into a formal custodial structure. Whether additional whitehat coordination or law-enforcement action returns more coins to a recovery trust like this one remains an open question.