Whitehat hackers have moved 52.37 BTC from wallets affected by the Coldcard exploit to an address associated with a newly established recovery trust, Galaxy Digital research chief Alex Thorn said.
The receiving address contains an OP_RETURN message that directs users to “claim:cryptorecoverytrust dot com.” The transfer is part of the ongoing effort to secure and recover funds connected to the Coldcard hardware-wallet attack.
The exploit began July 30 and unfolded through multiple waves of attacks, tracked as Waves 1, 2 and 3. The incidents are estimated to have caused more than $100 million in Bitcoin losses.
The vulnerability stemmed from the way some Coldcard wallets generated seed phrases. Instead of relying on the device’s dedicated random-number generator, affected wallets used a weaker software-based source of randomness. This potentially made the seeds predictable and allowed attackers to reconstruct them.
Coinkite, Coldcard’s manufacturer, has since patched the affected firmware. The update, however, cannot protect funds whose seed phrases had already been exposed before the fix was released.
Thorn said blockchain tracking indicates that not all Bitcoin removed from affected wallets was taken by attackers. Some transfers were carried out by whitehat operators, who used their cybersecurity expertise to secure vulnerable funds before malicious actors could access them.
The recovered Bitcoin is being held with the goal of eventually returning it to affected users.
The latest 52.37 BTC transfer was assembled from funds associated with Wave 2 of the tracked exploit, along with three addresses or transaction footprints identified as AA, AU and AX. The coins were sent to the recovery trust address containing the OP_RETURN message, and the transaction was confirmed in Bitcoin block 967,948.
Thorn said the transfer accounts for 2.8% of all tracked exploit funds. He also estimated that whitehat activity now represents about 40% of the funds associated with Wave 2.
An additional 3.0134 BTC with no earlier tracking history was transferred to the same recovery trust address. Thorn said the Bitcoin likely represents further Coldcard funds recovered by whitehat operators, but noted that this has not been confirmed.
Users affected by the exploit can check whether their Bitcoin was recovered by visiting cryptorecoverytrust.com and searching for their wallet addresses.

































