52 Bitcoin Tied to Coldcard Hack Transferred to Recovery Trust
Whitehat operators have moved 52.37 BTC associated with the Coldcard wallet exploit into an address tied to a newly created recovery trust, according to Alex Thorn, head of research at Galaxy Digital.
The receiving address carries an OP_RETURN message pointing users to “claim:cryptorecoverytrust dot com.” The transaction is part of an effort to secure Bitcoin taken from vulnerable wallets and facilitate its eventual return to affected owners.
The Coldcard exploit first emerged July 30 and subsequently spread through three waves of attacks, identified as Waves 1, 2 and 3. The combined losses are estimated at more than $100 million in Bitcoin.
The incident was traced to a flaw in seed generation that caused some wallets to use a weaker software-based randomness source rather than the device’s dedicated random-number generator. This weakness potentially enabled attackers to recreate affected wallet seeds.
Coldcard maker Coinkite has since released a firmware patch for the issue. However, wallets whose seed phrases were already exposed remain vulnerable even after the software update.
Thorn said blockchain analysis has identified cases where funds were moved by whitehat hackers instead of malicious actors. These ethical security researchers transferred the Bitcoin from exposed wallets to protect it from further theft while recovery arrangements were put in place.
The 52.37 BTC transaction included funds traced to Wave 2 of the exploit as well as three tracked footprints labeled AA, AU and AX. The Bitcoin was sent to the recovery trust address and confirmed in Bitcoin block 967,948.
According to Thorn, the transaction accounts for roughly 2.8% of all tracked exploit funds. About 40% of the Bitcoin associated with Wave 2 has now been identified as whitehat activity.
A further 3.0134 BTC was included in the same transfer despite having no prior tracking history. Thorn said the additional coins are presumed to represent more Coldcard funds recovered by whitehat operators, although that attribution remains unverified.
Victims can check whether their Bitcoin was among the recovered funds by entering their wallet addresses at cryptorecoverytrust.com.
Share this content:













