
DART, a digital-asset recovery organization, and independent white-hat researchers rescued just over 50 Bitcoin from wallets exposed by a Coldcard entropy vulnerability.
The rescue took place in late July, according to an August 17th blog post from DART and a September 9th X post from security researcher Nick Bax.
Finally able to say that at the end of July, I was involved in the rescue of ~50 BTC which were imminently going to be stolen due to the COLDCARD entropy flaw.
— Nick Bax (@bax1337) September 9, 2026
The funds are currently held by a Wyoming trust, which will ensure that funds are returned to their rightful owners.
Bax wrote that he helped rescue the funds "at the end of July," which were "imminently going to be stolen due to the COLDCARD entropy flaw." The Bitcoin is now held by a Wyoming trust that will ensure it reaches its rightful owners, he added.
Coinkite, the maker of the Coldcard hardware wallet, disclosed in late July that certain Mk2 and Mk3 firmware versions generated seeds with roughly 40 bits of entropy instead of the intended 128 bits.
The company traced the flaw to a build error that routed seed generation to a software pseudo-random number generator instead of the device's hardware random-number generator, DART reported.
Seeds with such reduced entropy could be reconstructed offline and tested against public Bitcoin addresses, without access to the physical device, backup card, or user credentials.
Estimated losses exceeded 1,000 Bitcoin by July 31st, according to DART.
DART's account put later losses at more than 1,596 Bitcoin across three confirmed waves, with total losses above $100 million and additional suspected activity still under review.
DART's internal recovery ledger showed just over 50 Bitcoin secured as of August 17th.
White-hat researchers identified vulnerable, funded addresses and moved the Bitcoin before malicious actors could act, DART said, adding that additional exposed assets and leads remain under review.
Rather than seek a bounty for the recovered funds, the researchers returned the Bitcoin to its owners.
The rescued Bitcoin was deposited into the Crypto Recovery Trust, a Wyoming statutory trust created and advised by national security attorneys at Steptoe LLP.
It was not held in a researcher's personal wallet or DART's own operating funds, DART wrote.
The trust documents each rescue, segregates recovered funds from DART's and researchers' own assets, and conducts blockchain analysis, ownership checks, and sanctions screening before returning verified owners' Bitcoin.
Funds tied to sanctions, criminal proceedings, or competing claims instead follow the applicable legal process, DART outlined.
Coinkite has since released corrected firmware, though installing it does not repair an already affected seed, DART added.
Affected owners should generate a new seed only on fixed firmware, verify a test transaction, and migrate remaining balances without entering seed phrases into any website.
