A failure users could not see
A hardware wallet can be offline, physically secured, and operated carefully, yet still be vulnerable if the seed at its foundation was never sufficiently unpredictable.
In late July 2026, Coinkite disclosed that certain COLDCARD firmware versions generated wallet seeds with materially less entropy than intended. Its technical account describes a build and integration error that routed seed generation to a deterministic software pseudo-random number generator instead of the device's hardware random-number generator. Coinkite estimated roughly 40 bits of effective entropy for affected Mk2 and Mk3 seeds, rather than the intended 128 bits, with later affected models also falling below the target.
That difference is not academic. A seed with adequate entropy is beyond practical enumeration. A seed drawn from a drastically smaller set can be reconstructed offline and tested against public Bitcoin addresses. An attacker does not need the device, the backup card, or a phishing response.
The loss estimates kept moving
Because Bitcoin transactions are public but attribution is analytical, early estimates varied. Bitcoin Optech reported that estimated losses had exceeded 1,000 BTC by July 31. Days later, Decrypt, citing Galaxy Research, reported more than 1,596 BTC across three confirmed waves and losses above $100 million, with additional suspected activity still being evaluated.
The precise aggregate will continue to be refined. The operational reality was already clear: affected addresses faced an active race between owners, attackers, and defenders.
Just over 50 BTC moved out of danger
According to DART's internal recovery ledger as of August 17, 2026, DART and independent white-hat researchers have secured just over 50 BTC from addresses exposed during the incident. The work is continuing.
The white hats were essential. They identified vulnerable funded addresses, developed defensible evidence, and acted to preserve assets before malicious actors could take them. DART coordinated the recovery and custody path. We are intentionally withholding wallet addresses, researcher identities, and operational methods while active work and ownership verification continue.
The rescued Bitcoin was not left in a researcher's personal wallet or mixed with DART operating assets. It was deposited into the Crypto Recovery Trust, a purpose-built Wyoming statutory trust created and advised by national security attorneys at Steptoe LLP.
Why the recovery trust exists
Moving vulnerable Bitcoin to safety answers an urgent technical question: how do we stop the next theft? It does not, by itself, answer the legal and fiduciary questions that follow. Who may hold the assets? How is lawful control documented? How are competing claims evaluated? What happens if sanctions, criminal proceeds, or another legal restriction is identified?
The trust creates an independent, documented process for answering those questions. Its primary purpose is to safeguard insecure virtual currency and return it to the verified original owner where lawful and possible.
Document the rescue
The trust verifies the contributor, the lawful basis of the recovery, the affected addresses, and the chain of custody before accepting assets.
Segregate and secure
Accepted assets are held through purpose-specific, auditable custody rather than commingled with the operations or property of DART or a researcher.
Investigate and screen
The process includes blockchain and source-of-funds analysis, ownership diligence, exchange-record review, sanctions screening, and documented notice efforts.
Return or lawfully route
Verified owners can pursue return. Assets subject to sanctions, criminal-process restrictions, competing claims, or unresolved ownership follow the applicable legal channel.
The trust is not a shortcut around ownership rights, due process, or law enforcement. It is the opposite: a structure designed to preserve assets while those obligations are handled transparently and consistently.
Why DART partnered with CryptoRecoveryTrust.com
Digital-asset recovery does not fit neatly inside a single discipline. A technically valid transaction can still raise questions involving fiduciary duties, sanctions, anti-money-laundering controls, evidence, custody, government investigations, and litigation.
CryptoRecoveryTrust.com was created to turn emergency technical action into a repeatable legal and fiduciary process. Attorneys from Steptoe's multidisciplinary Blockchain and Cryptocurrency practice bring experience across custody, transaction surveillance, sanctions, AML, government enforcement, and digital-asset disputes. Its role as counsel to the trustee adds legal rigor when rescued property may belong to an owner who has not yet been identified or verified.
That separation matters. Researchers can focus on identifying and securing vulnerable assets. DART can coordinate the technical recovery record. The trust can preserve and administer the property under a defined, owner-first framework.
An invitation to researchers and white hats
Security researchers often find the problem before an owner, custodian, or public authority knows there is one. Until now, there have been few credible places to bring lawfully rescued digital assets without creating new custody, liability, or ownership risk.
If you have lawfully secured at-risk digital assets, identified a credible lead to assets that remain vulnerable, or hold evidence that may support a recovery, contact DART. Begin with public wallet addresses, transaction identifiers, and a high-level description only. Do not send seed phrases, private keys, PINs, recovery codes, or raw exploit material through the web form. We will establish an appropriate secure channel before requesting sensitive technical information.