Whitehat operators have moved 52.37 Bitcoin from funds linked to the Coldcard hardware wallet hack into an address associated with a newly formed recovery trust, according to Galaxy Digital Head of Research Alex Thorn. The transfer is part of the continuing recovery effort following the July Coldcard exploit, which resulted in estimated losses of more than $100 million in Bitcoin.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN “claim:cryptorecoverytrust dot com” in block 967,948
these white hatted funds represent 2.8% of the coldcard exploit https://t.co/c5eYeQMxHQ
— Alex Thorn (@intangiblecoins) September 21, 2026
Thorn said the transferred coins were recovered by ethical security researchers rather than malicious attackers. The 52.37 BTC represents about 2.8% of the tracked exploit funds and was sent to an address carrying a message linking it to the Crypto Recovery Trust.
The Coldcard exploit began on July 30 and involved several waves of attacks. The affected wallets had generated seeds using a weaker software-based source of randomness instead of the hardware wallet’s dedicated random-number generator.
That weakness meant some wallet seeds could potentially be reconstructed by attackers. Once a vulnerable seed was exposed, the Bitcoin associated with the wallet could be at risk.
Coldcard manufacturer Coinkite has since patched the relevant firmware. However, the update does not remove the risk from funds associated with seeds that were already exposed under the earlier software version.
The latest movement involves what the crypto security community calls whitehat activity. Whitehat operators are cybersecurity professionals who use similar technical methods to identify or secure vulnerabilities but do so with the aim of protecting affected users rather than stealing funds.
According to Thorn, the 52.37 BTC was consolidated from funds associated with Wave 2 of the Coldcard exploit, along with three other tracked footprints identified as AA, AU and AX.
The coins were transferred to an address containing an OP_RETURN message referring to the Crypto Recovery Trust. The transaction was confirmed in Bitcoin block 967,948.
Source: x.com
Thorn said the 52.37 BTC represents about 2.8% of the total tracked exploit funds. He also reported that roughly 40% of Wave 2 has now been identified as whitehat activity.
An additional 3.0134 BTC with no previous tracking history was also sent to the recovery-trust address in the same transaction. Thorn said this is presumably additional Bitcoin recovered by whitehat operators but stressed that this has not been confirmed.
The recovery trust is intended to provide a route for returning recovered funds to victims. Users affected by the Coldcard incident can check whether their Bitcoin was among the recovered funds by searching their wallet addresses through the recovery trust’s website.
The movement highlights the complicated nature of recovering cryptocurrency after a wallet security incident. Once funds have moved on the Bitcoin blockchain, identifying their origin and establishing which victims they belong to can require detailed transaction analysis.
The latest transfer does not mean that all affected funds have been recovered. Instead, it represents another identifiable batch of Bitcoin that whitehat operators appear to have secured and moved into a designated recovery address.
For Coldcard users affected by the exploit, the key issue now is whether their specific wallet addresses appear among the funds being tracked and recovered.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like









Leave a comment