Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust

White-hat operators consolidated 52.37 BTC tied to the July Coldcard hardware wallet exploit into an address linked to a newly formed recovery trust, Galaxy Digital researcher Alex Thorn reported. The transaction includes an OP_RETURN message pointing to cryptorecoverytrust.com and was recorded in block 967,948.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust

Why It Matters

The move highlights ongoing efforts by ethical hackers to secure and potentially return funds exposed by the Coldcard vulnerability, which has already led to large-scale losses and remains a live security concern for affected wallets. It also provides a mechanism for victims to check whether their addresses were part of the recovery sweep.

Key Facts

  • Amount moved: 52.37 BTC
  • Associated exploit: Coldcard hardware wallet exploit beginning July 30
  • Estimated losses from exploit: Over $100 million
  • OP_RETURN message: claim:cryptorecoverytrust dot com
  • Blockchain confirmation: Block 967,948 confirmed transaction

White-hat operators have transferred 52.37 bitcoin tied to the July Coldcard hardware wallet exploit into an address associated with a newly established recovery trust, according to Alex Thorn, Head of Research at Galaxy Digital. The consolidated funds were moved from Wave 2 of tracked exploit outputs and three footprints labeled AA, AU and AX. The transaction includes an OP_RETURN note directing to cryptorecoverytrust.com and was confirmed in block 967,948.

The Coldcard breach began on July 30 and unfolded in multiple waves, with attackers exploiting a lapse that caused wallets to generate seeds using weaker software-based randomness instead of the device’s dedicated random number generator. That flaw allowed some seeds to be reconstructed by attackers, producing estimated losses exceeding $100 million. Coldcard maker Coinkite has since issued a firmware patch, but funds created from the vulnerable seeds remained at risk.

Thorn said the 52.37 BTC represents roughly 2.8% of all funds tracked from the exploit, and that about 40% of the Wave 2 funds have been identified as having been moved by whitehats rather than malicious actors. In the same transaction, an additional 3.0134 BTC with no prior tracking history also flowed into the recovery-trust address; Thorn described this as likely additional white-hat recovered Coldcard funds but noted it is unconfirmed.

The recovery trust has set up a searchable portal at cryptorecoverytrust.com where victims can enter wallet addresses to see whether their coins were among those swept and consolidated. The white-hat activity is presented as an effort to secure exposed funds until they can be returned to rightful owners, while the broader incident continues to underscore ongoing risks from the original seed-generation vulnerability.

Keep Reading