Not every coin drained from a Coldcard wallet this summer went to a thief. Some of it went to people trying to give it back, and this week 52.37 BTC of that money landed in one place.
“Whitehat operators” moved the coins to an address tied to a newly formed recovery trust, Galaxy Digital Head of Research Alex Thorn said. The transfer is the latest turn in the fallout from July’s Coldcard hardware wallet exploit.
Whitehats swept the coins before attackers could
Thorn said a share of the coins pulled out of victim wallets wasn’t taken by malicious actors. Whitehats took it. These are ethical security professionals who use hacking skills to find and fix weaknesses.
They swept the funds to keep them safe until the money could be returned. It’s an odd kind of rescue. Moving someone else’s bitcoin without asking is how theft looks on-chain too, which is why this week’s tracking data matters.
The 52.37 BTC sweep came from Wave 2 of the tracked exploit funds. It also pulled in three footprints labeled AA, AU and AX. All of it went to an address carrying an OP_RETURN message that reads “claim:cryptorecoverytrust dot com.” The transaction confirmed in block 967,948.
What the numbers say
Thorn said the amount is 2.8% of the total tracked exploit funds. He also said about 40% of Wave 2 has now been identified as whitehat activity.
That second figure is the one to watch. A big chunk of one attack wave may not have been theft at all.
A separate 3.0134 BTC with no prior tracking history flowed into the same CRT address in the same transaction. Thorn said it’s presumably more whitehat-recovered Coldcard funds. He stressed that this remains unconfirmed, so don’t count it as recovered money yet.
How the Coldcard exploit worked
The hack began on July 30. More batches followed over the next days, tracked as waves 1, 2 and 3, and estimated losses passed $100 million in bitcoin. BTC was trading at $84,251.41.
The flaw sat in seed generation. Attackers exploited it so wallets built seeds from a weaker software-based random number source instead of the wallet’s dedicated random number generator. Some of those seeds could then be rebuilt by hackers.
That’s a bad failure for a hardware wallet. A dedicated random number generator is one of the main reasons to pay for a device instead of keeping keys in software.
The patch doesn’t save old seeds
Coinkite, which makes Coldcard, has patched the firmware since then. But funds sitting under seeds made before the fix are still at risk, patch or not.
A firmware update fixes the generator. It can’t fix a seed that was already weak when it was created. If you made your seed on the vulnerable firmware, updating alone doesn’t protect your coins.
What victims should do now
You can check whether your funds were among those recovered. Go to cryptorecoverytrust.com and search your addresses.
If your address shows up, the money is in the trust’s hands, not an attacker’s. If it doesn’t and your seed dates from before the patch, move whatever’s left to a newly generated seed today.