Whitehats Shift 52 BTC Linked to Coldcard Hack Into Recovery Trust

A group of whitehat operators has transferred 52.37 BTC tied to the Coldcard hardware-wallet exploit to an address connected to a newly created recovery trust, according to Galaxy Digital’s head of research, Alex Thorn.

The destination address contains an OP_RETURN note directing users to “claim:cryptorecoverytrust dot com,” signaling that the funds are being held for potential recovery by affected users.

The Coldcard exploit began on July 30 and spread across three identified attack waves. The incidents resulted in estimated Bitcoin losses exceeding $100 million.

The underlying issue involved a weakness in seed generation. Some Coldcard wallets relied on a software-based source of randomness rather than the device’s dedicated random-number generator, potentially making their seed phrases vulnerable to reconstruction by attackers.

Coldcard manufacturer Coinkite has since issued a firmware update to address the vulnerability. However, the patch does not remove the threat to wallets whose seed phrases were already compromised before the update.

According to Thorn, blockchain activity shows that some Bitcoin taken from vulnerable wallets was moved by whitehat hackers rather than malicious attackers. These ethical security operators transferred the assets to protect them from theft while recovery efforts were organized.

The latest transaction moved 52.37 BTC from funds associated with Wave 2 of the exploit, together with three tracked footprints identified as AA, AU and AX. The transfer was sent to the recovery trust address and confirmed in Bitcoin block 967,948.

Thorn said the 52.37 BTC represents approximately 2.8% of the total exploit funds currently being tracked. About 40% of Wave 2 funds have now been identified as activity involving whitehat operators.

The same transaction also included another 3.0134 BTC that had not previously been tracked. Thorn said those coins are believed to be additional funds recovered by whitehat operators, although there is no confirmation yet that they originated from the Coldcard exploit.

Affected users can check whether their funds were recovered by searching their wallet addresses at cryptorecoverytrust.com.