White Hats Secure 52.37 Bitcoin (BTC) from Coldcard Exploit in Recovery Trust

Ethical researchers appear to have done what many Coldcard victims had hoped for: they reached 52.37 bitcoin before thieves could empty the exposed wallets. Alex Thorn, Galaxy Digital’s (NASDAQ: GLXY) head of firmwide research, said those coins have now been gathered into a single address tied to Crypto Recovery Trust.

The move was recorded in Bitcoin block 967,948.

According to Thorn’s on-chain review, the bitcoin came from Wave 2 of the exploit plus clusters he had labeled Footprints AA, AU, and AX. An embedded OP_RETURN note pointed claimants to cryptorecoverytrust.com.

Thorn estimated the recovered amount at about 2.8 percent of the funds his team has tied to the incident.

He also said roughly 40 percent of Wave 2 activity now looks like protective sweeps rather than theft.

The underlying problem dates to a March 2021 Coldcard firmware issue.

Seed generation on affected devices fell back to a weak software random-number source instead of the hardware generator.

Effective entropy dropped far below the intended 128 bits, leaving some seeds guessable.

Attackers began draining vulnerable single-signature addresses in late July 2026.

Losses tracked by Galaxy and others have been measured in the thousands of bitcoin and well over $100 million at peak estimates, with multiple independent operators involved.

White-hat teams scanned for still-exposed wallets and moved coins they could reach first.

Earlier reports from groups such as DART described more than 50 bitcoin secured in late July and August and placed in the same Wyoming statutory trust.

The September consolidation made that custody visible on-chain.

An extra 3.01 bitcoin that had not previously been mapped also entered the trust address in the same transaction; Thorn treated that slice as likely additional recovered funds but did not confirm it.Crypto Recovery Trust is structured to hold the assets while ownership is verified.

Claimants can check addresses on the trust site and submit proof without handing over private keys.

The arrangement is meant to keep recovered coins segregated from any researcher’s personal wallet and to create a documented path for return where the law allows.

The recovered slice is small next to the overall loss.

Large portions of Wave 1 remain untouched in attacker-controlled addresses, and much of the rest of Wave 2 is still at risk.

Firmware updates can stop new weak seeds from being created, but they cannot strengthen seeds that were already generated with the flawed process.

Users whose funds were created on vulnerable firmware have been told to move coins to new addresses generated on current software

The episode underlines a hard limit of self-custody: the key is only as strong as the process that produced it. For a subset of victims, white-hat intervention and a dedicated legal vehicle have at least created a chance of restitution that would not have existed if the coins had reached the attackers first.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend