Whitehats Move 52.37 BTC from Coldcard Hack to Recovery Trust

Ethical hackers moved 52.37 bitcoin to a new trust address, representing 2.8% of the total tracked funds from the July exploit.
Key points
- White-hat hackers moved 52.37 BTC to a recovery trust address linked to the Coldcard exploit.
- The Coldcard hack caused over $100 million in losses by exploiting weak random number generation.
- Victims can check the cryptorecoverytrust.com website to see if their specific funds were recovered.
White-hat operators moved 52.37 bitcoin to a recovery trust address. Galaxy Digital identifies this as a significant portion of the tracked exploit funds.
The transfer includes coins from the second wave of the Coldcard hack. An additional 3.0134 bitcoin with no prior tracking history joined this sweep.
Exploit Mechanics and Loss Scale
Attackers exploited weak software randomness to reconstruct wallet seeds. This flaw allowed them to bypass the hardware wallet's dedicated random number generator.
The July 30 exploit caused estimated losses exceeding one hundred million dollars. Coinkite has patched the firmware, but exposed funds remain at risk.
Recovery Trust and Victim Access
The funds moved to an address with a specific OP_RETURN message. This message directs users to the cryptorecoverytrust dot com website for claims.
Victims can search their wallet addresses on the site to verify recovery. This process allows them to confirm if their specific funds were secured.
White-Hat Activity Metrics
The moved amount represents 2.8 percent of all tracked exploit funds. Analysts estimate that roughly 40 percent of Wave 2 activity is white-hat.
Galaxy Digital head Alex Thorn confirmed the white-hat involvement in the sweep. The transaction was confirmed in block 967,948 of the bitcoin network.






