xiyu|Aug 08, 2026 06:55
If the stolen funds from Coldcard are actually recovered, the refund process is going to be quite tricky.
After the low-entropy vulnerability is disclosed, attackers can continue enumerating affected seeds, controlling the receiving and change addresses derived from the old wallets. Sending the money back would be like putting the recovered BTC back into a public target range; signatures from the old addresses can't prove identity either, since attackers can sign them too.
The refund process should follow two separate tracks:
Old addresses should only be used to reconstruct losses, with victim identities cross-verified through withdrawal records before the incident, police reports, and platform logs;
Compensation funds should only go to new addresses generated from entirely new high-entropy seeds, followed by new address signatures, a cooling-off period, and small test transactions.
Returning the original coins in the original amount is fine, but absolutely not to the original addresses.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink