Custody You Didn't Ask For: The White-Hat Rescue Fund Problem
Sweeping weak-entropy wallets "for safekeeping" is a one-way door. This is an operational risk assessment of a thing that looks, from the outside, like a weekend project.
Date: August 4, 2026 · Author: Karma-X Security Research Team
Topic: Incident response · disclosure ethics · custody risk · Context: July–August 2026 hardware wallet entropy incident
Related: The $38 Million Random Number · Delta PIN → Bitcoin Private Key Recovery · Karma-X
The idea that surfaces every time
Every time an entropy failure goes public, the same proposal appears within hours: someone should sweep the vulnerable wallets before the thieves finish. Move the coins somewhere safe, hold them in escrow, verify the rightful owners, give them back. A rescue fund. White-hat custody. Defensive seizure.
The instinct is decent, and the reasoning has real force. When a seed-generation flaw collapses a keyspace from 128 bits to something searchable, the addresses are public, the derivation criteria are public, and the race is already running. In the July 2026 incident, an attacker moved roughly 1,300 UTXOs inside a three-block window; subsequent waves pushed the running total past 1,300 BTC across thousands of addresses. Every hour a vulnerable UTXO sits unswept is an hour it belongs to whoever grinds fastest.
So the argument writes itself: if a defender doesn't move first, a black hat will. That argument is sound right up until the moment you broadcast, and then you own a set of problems most people considering this have never enumerated.
This post enumerates them. Not to lecture anyone into inaction — the impulse to help is the right impulse — but because the people floating this idea in Discord threads and conference hallways are consistently underestimating what they would be signing up for.
Risk 1: The transaction is indistinguishable from the crime
On-chain, a rescue sweep and a theft are byte-for-byte the same class of event: a valid signature, a spend, a consolidation address. There is no OP_GOOD_INTENTIONS. Bitcoin has no concept of authorization, only of signature validity — which is precisely why the protocol cannot vindicate you. The thing that makes the sweep possible is the same thing that makes it unprovable as a rescue.
Your intent lives entirely in what you do afterward: the disclosure, the claims process, the returns, the accounting. Which means at the instant of the act you have no defense at all. You have a promise to construct one later. Every hour between the sweep and the public accounting is an hour in which the only available reading of your behavior is the unflattering one — and that window is exactly when the incident is loudest and least forgiving.
Risk 2: There is no undo
This is the part that gets waved past, and it is the one that should stop the conversation.
You cannot put the coins back. "Back" is an address whose private key is derivable by anyone who read the same advisory you did. Returning funds to origin is not remediation — it is re-arming the trap, and the next sweep bot takes them within minutes. The original wallets are permanently uninhabitable. That is not a policy choice; it is a property of the vulnerability.
Risk 3: Proof of ownership is broken by construction
Here is the cruelest technical irony in the whole scenario.
The canonical way to prove control of a Bitcoin address is to sign a message with its key — BIP-137, BIP-322, whatever your tooling supports. But in a weak-entropy incident, the key is guessable by definition. Anyone who can enumerate the reduced keyspace can produce a valid signature for any affected address. The standard proof mechanism is worth exactly nothing here, and it fails in the one scenario where you need it most.
So you fall back to secondary evidence: purchase receipts, device serial numbers, xpub derivation history, wallet software backups, timing correlation, notarized affidavits. Every one of these is forgeable or contestable, and none is authoritative. Meanwhile the affected addresses and their balances are public, which means an adversary constructing a fraudulent claim has perfect information about exactly what to claim and how much to claim it for.
Risk 4: You accidentally started a financial institution
Holding other people's assets and distributing them on their instruction is a recognizable activity with a substantial body of regulation attached to it in most jurisdictions. Whether any particular regime applies to an unpaid volunteer holding recovered coins is a question for lawyers. But "I didn't intend to be a custodian" has historically not been a durable structural argument, and intent is not usually an element of the registration requirement.
Set the legal question aside entirely and the operational questions are still yours:
- What is the custody model? A single-sig hot key holding eight figures is negligent on its face. A multisig means recruiting co-signers who now share every exposure in this post.
- What is the key ceremony? Generated on what hardware, with what entropy, witnessed by whom, backed up where? You are being trusted by people who just got burned by exactly this question.
- What happens to unclaimed coins? In year one? Year five? Unclaimed-property and escheatment frameworks exist for precisely this situation and were not drafted with you in mind.
- Who pays for it? Legal review, key ceremonies, claim processing, and a support burden from thousands of frightened people are not free. Taking a fee to cover it changes the character of the entire enterprise.
- What is the succession plan? If you are hit by a bus, the fund is gone and every claimant becomes a creditor of your estate.
- What are the tax consequences? Of receipt, of holding across a price move, of distribution. In multiple jurisdictions simultaneously.
None of these have good weekend-project answers. All of them have to be answered before the sweep, because after the sweep you are answering them under time pressure with an audience.
Risk 5: You have painted a target on yourself
A publicly known individual holding a publicly known consolidation address with a publicly known balance is a threat model unto itself.
- Technical: you are now the highest-value single target in the incident, and every adversary knows your exact balance in real time.
- Physical: the wrench attack is not a meme, it is a documented category with a body count of ruined lives. Consolidating thousands of victims' coins under one person's control creates the precise conditions that category selects for.
- Legal: victims of a wallet-entropy failure are globally distributed, which means the set of plausible forums is large and you do not get to choose from it. Where you sat, where the victims sat, where the exchanges sat, and where your consolidation address's counterparties sat can all matter.
That is a lot of coin flips for something you did on a Saturday because it seemed better than doing nothing.
Risk 6: The taint is permanent
Chain analytics firms cluster and label addresses, and they do it fast — within hours of a public incident. Those labels propagate to exchanges, custodians, payment processors, and compliance desks, and they are considerably easier to acquire than to shed.
Even a flawlessly executed rescue that returns every satoshi to a verified owner leaves your addresses — and, depending on the heuristic, any address that later touches them — annotated in commercial datasets indefinitely. Your future counterparties will see the annotation. They will not see your blog post explaining it.
Risk 7: "Someone worse would have taken it" is not a defense you control
The counterfactual is probably true. It is also not yours to invoke. Nobody appointed you, no owner consented, and the reasoning generalizes badly — it is the same argument the next person will use in a case with far less obvious merit, and the one after that in a case with none.
As a policy matter, "I may seize your property if I judge it insufficiently protected" is not a rule anyone wants running loose in this ecosystem. Including you, on the day someone applies it to a wallet of yours that turns out to have been generated on the wrong firmware.
Risk register
| Risk | Why it bites | Mitigable before acting? |
|---|---|---|
| Indistinguishability | The sweep and the theft are the same on-chain event; intent exists only in later conduct. | Partially — pre-published intent, pre-arranged counsel, immediate public accounting. |
| No undo | Origin addresses are permanently unsafe; you cannot restore the prior state. | No. Structural. |
| Broken ownership proof | Signature-based proof is worthless when the key is guessable; fallback evidence is forgeable. | No. Structural to the vulnerability class. |
| Accidental custodian | Custody, distribution, escheatment, tax, and succession obligations attach immediately. | Partially — entity formation, counsel, insurance, documented policy. All slow. |
| Target concentration | Technical, physical, and multi-jurisdiction legal exposure concentrated on one person. | Partially — multisig with co-signers, opsec. Transfers risk, does not remove it. |
| Permanent taint | Analytics labels outlive the incident and follow downstream addresses. | No. Labels are applied by third parties on their own criteria. |
| Counterfactual defense | "A thief would have taken it" is not a recognized authorization and generalizes badly. | No. Not yours to invoke. |
Four of seven are structurally unmitigable. That ratio is the whole argument.
What lower-risk looks like
The uncomfortable truth is that the highest-value defensive work in an entropy incident does not involve touching anyone's funds at all.
- Publish the derivation criteria, not the keys. Give owners exactly what they need to determine whether they are affected — firmware versions, date ranges, device generations, the specific conditions that trigger the weakness. This is the single highest-leverage output available to a researcher during an incident.
- Ship self-rescue tooling. A verifiable, auditable, offline tool that lets an owner check their own wallet and move their own coins to a freshly generated seed puts the decision, the keys, and the liability exactly where they belong. It scales without you.
- Escalate through the vendor. The party that shipped the bug has the customer list, the notification channel, the legal department, and the obligation. Push there first and loudly.
- Engage counsel — and, where appropriate, law enforcement — before acting. Not after. The sequencing is most of the difference between a defensible position and a confession.
- Accept that some coins are lost. This is the hardest one and it is frequently the correct one. Not every problem has an intervention that improves it.
Note what these have in common: none of them requires you to hold anyone else's property, and all of them scale to thousands of affected users without a claims process, a multisig quorum, or a lawyer on retainer.
The actual fix is upstream
Every white-hat rescue proposal is a response to a failure that already happened, and the structural problem is that post-hoc heroics cannot be made safe — not for the rescuer, and not reliably for the owner either. By the time a rescue fund is on the table, every remaining option is bad; the argument is only about which one is least bad.
What is under an owner's control is the entropy that produces their seed and the recovery path they design before they need it. A BIP-39 passphrase generated independently of the device sits outside any vendor's RNG and neutralizes an entire class of these failures. Sufficient dice rolls do the same. Multi-vendor multisig means no single vendor's entropy bug is fatal.
And recovery — real recovery, the kind that survives a lost seed or a dead holder — should be an architectural decision made in advance by the owner, not a favor improvised after the fact by a stranger with a GPU cluster and good intentions.
Learn more: https://karma-x.io/timecapsule/
This is the prevention-over-detection thesis applied to custody: the window in which you have good options is before the incident, and it closes fast.
Q&A anticipated
"Isn't it strictly better than letting a thief take it?"
For the individual owner, in isolation, probably yes — if the rescue works, the claims process is sound, and the fund survives long enough to distribute. That is three conditionals, each of which has failed in real incidents. And "strictly better than the worst case" is not the standard by which anyone will evaluate you; the standard is "why is this person holding my coins." Being better than a thief is a low bar that does not clear any of the seven risks above.
"What if I announce my intent publicly before sweeping?"
It genuinely helps — it is the single cheapest thing you can do to establish contemporaneous intent, and it costs you nothing. It also tips off every competing sweeper, converts a quiet race into a public one, and does not resolve the structural risks: you still cannot undo it, you still cannot verify claims, and you are still a custodian. Necessary, not sufficient.
"What about sweeping and immediately returning to an address the owner names?"
That is the best version of the idea, and it collapses on Risk 3. To return to an address the owner names, you must first establish that they are the owner — and the only cryptographic mechanism for doing so is broken by the vulnerability you are responding to. In practice you are accepting attestations from strangers about coins you hold, with the balances publicly visible to anyone who wants to fabricate a claim.
"Does incorporating an entity fix this?"
An entity is a genuine improvement over doing it personally — it creates a governance structure, a documented policy, a place for insurance to attach, and a survivor if you are hit by a bus. It does not change the on-chain indistinguishability of the sweep, does not restore the ability to undo, and does not make claim verification tractable. It converts some personal exposure into organizational exposure. That is worth something. It is not a solution.
"Is Karma-X saying researchers should never intervene?"
No. We are saying that intervention which takes custody of third-party assets is categorically different from every other kind of defensive research, and that the people proposing it are usually reasoning about the first ten minutes rather than the next ten years. Disclosure, tooling, and vendor pressure are interventions too, they help more people, and they do not require you to become a custodian, an adjudicator, a target, and a potential defendant simultaneously.
"Has anyone actually done this successfully?"
There are cases where funds were recovered and returned, and the people involved generally describe the experience as considerably worse than they expected — long, expensive, legally fraught, and reputationally ambiguous even on success. Notably, these are almost always situations with a single identifiable counterparty (a protocol, a DAO, a company) rather than thousands of anonymous individual owners. The multi-victim self-custody case is materially harder, and we are not aware of a clean precedent for it.
The bottom line
If you are weighing a rescue fund right now, the question is not whether your intentions are good. Assume they are. The question is whether you are prepared to be a custodian, an adjudicator, a defendant, and a target — simultaneously, indefinitely, and without an exit.
Most people asking the question have not priced any of the four. That is the reason to write this down before the next entropy bug rather than during it.