Latest News

Whitehats Moved 52 Bitcoin From the Coldcard Hack Into a…

Ethical hackers have swept 52.37 bitcoin, worth about $4.5 million, out of wallets exposed by July’s Coldcard hack and moved it into a newly formed recovery trust set up to return the funds to victims. The transfer was flagged by Galaxy Digital’s head of research, Alex Thorn, who tracked the coins on-chain to a single address carrying an embedded message pointing recipients to a claims site. What makes the move unusual is the part that did not happen: the researchers reached the coins before the attackers could and did not ask for a bounty.

The recovery is the latest chapter in a saga that has run since late July, when a flaw in certain Coldcard devices let attackers reconstruct wallet keys and drain bitcoin from holders who believed self-custody had made them safe. This week’s sweep is a genuine rescue, but a partial one, and the gap between what was recovered and what the Coldcard hack took is the real measure of the damage.

❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️

52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN “claim:cryptorecoverytrust dot com” in block 967,948

these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ

— Alex Thorn (@intangiblecoins) September 21, 2026

Whitehats Swept 52.37 BTC in Block 967,948

The consolidation was recorded on-chain and is straightforward to trace. Whitehat operators gathered 52.37 BTC from Wave 2 of the tracked exploit funds, along with three transaction footprints labeled AA, AU and AX, and sent them to a fresh address in block 967,948, a transaction carrying 20 inputs and 480 outputs. The address includes an OP_RETURN message, a small piece of data written directly into the Bitcoin blockchain, reading “claim:cryptorecoverytrust dot com,” which directs affected users to a claims site.

The 52.37 BTC represents about 2.8% of the total funds tracked to the exploit, and roughly 40% of Wave 2 has now been identified as whitehat activity rather than theft. An additional 3.0134 BTC with no prior tracking history flowed into the same trust address in the transaction, which Thorn said is presumably more whitehat-recovered Coldcard money, though he stressed that part remains unconfirmed.

The Wyoming Recovery Trust, and Why No One Asked for a Bounty

The structure behind the rescue is what separates it from an anonymous on-chain move. The effort was organized in part by DART, the Digital Asset Recovery Trust, which said independent whitehat researchers identified the vulnerable addresses and moved the coins before malicious operators could sweep them, in its own report on the recovery.

The recovered coins sit in what DART describes as “a purpose-built Wyoming statutory trust created and advised by national security attorneys at Steptoe LLP,” registered as the Recovered Digital Asset Statutory Trust of Wyoming, and set up to keep recovered bitcoin separate from researcher and operating funds while rightful ownership is established.

Most recovery stories end with a negotiated cut, where whitehats keep a percentage in exchange for returning the rest, but the researchers in this case did not request one. That does not make the claims process automatic, and affected owners will still have to prove control of the compromised addresses to reclaim their share, but it removes the adversarial pricing that usually accompanies these rescues.

Investor Takeaway

This is a real recovery with a legal structure behind it, since the funds sit in a Wyoming trust advised by outside counsel rather than in an anonymous wallet, which is what separates it from a vague on-chain promise.

The March 2021 Firmware Flaw That Made Seeds Guessable

The vulnerability that made all of this possible sits deep in how the affected devices created keys. A firmware defect caused the seed-generation path on certain Coldcard models to fall back to a software pseudorandom generator instead of the device’s dedicated hardware random-number generator, which drained the randomness that is supposed to make a seed phrase unguessable. That predictability meant attackers could reconstruct compromised seeds offline, with no network access or physical possession of the device required.

The flaw dated to a March 2021 firmware update and went undetected for more than five years, so some wallets had been exposed the entire time. Coinkite, the maker of Coldcard, took full accountability for the firmware bug, apologized, patched the firmware and destroyed remaining vulnerable inventory. The patch does not repair the damage, though: a seed generated with weak randomness stays weak after an update, because the private keys do not change, which is why Coinkite has urged affected users to generate entirely new seeds and migrate their funds.

Why 52 BTC Is Only a Fraction of What the Coldcard Hack Took

The recovery reads better in isolation than against the total. Estimates of the losses vary with how many attack waves and clusters are counted, running from roughly 594 BTC in the first wave to as much as 1,816 BTC across more than 4,500 addresses, with FinanceFeeds’ own tracking putting the toll near $112 million as related hardware-wallet flaws emerged. Against that, a 52 BTC recovery is a meaningful gesture but a small dent.

The latest whitehat sweep recovered about 2.8% of the funds tracked to the exploit, leaving the large majority outstanding. Data: Galaxy Research / Alex Thorn · Chart: FinanceFeeds.

The incident has already reshaped how the Bitcoin community talks about self-custody. The scale of the Coldcard hack triggered one of the largest coordinated bitcoin migrations since the FTX collapse as holders raced to move funds off exposed seeds, and it prompted Binance founder Changpeng Zhao to urge holders to spread funds across several wallets rather than trust a single seed-generation process. The lesson underneath the recovery is structural: hardware wallets move risk from a custodian to code, and a single weak randomness source can undo the entire promise of holding your own keys.

Affected Coldcard Holders Must Treat Exposed Seeds as Burned

The practical steps are the same whether or not a holder’s funds were among those recovered. Anyone who generated a seed on an affected Coldcard model should treat any address touched by the flaw as permanently compromised, generate an entirely new seed on patched hardware, and move funds to addresses derived from that new phrase. A key that was once guessable stays guessable, so installing the firmware fix alone does not restore safety.

Victims can check whether their addresses were part of the recovery, but the verification should run through the on-chain provenance and DART’s disclosure rather than blind trust in any site, since fake recovery pages are a well-worn tactic against hack victims. The migration itself carries its own risks, because moving funds can alert an attacker watching the address, and entering a recovery phrase into an unsafe device can open a fresh route to theft, so the safest path is a carefully verified transfer to newly generated keys.

Investor Takeaway

Treat exposed seeds as permanently burned, since a weak seed stays weak after any patch, so the only real fix is new keys generated on patched hardware, not a firmware update.

You may also like