Ethical operators have transferred 52.37 BTC into an address connected to a newly established recovery trust, marking another development in the ongoing aftermath of July’s Coldcard hardware wallet breach, according to Alex Thorn, Head of Research at Galaxy Digital.
The Coldcard crypto hardware wallet breach launched on July 30, featuring multiple waves (waves 1, 2, and 3) of subsequent attacks that triggered estimated losses surpassing $100 million in bitcoin.
Bad actors took advantage of a vulnerability that forced wallets to utilize a weaker software-driven random number generator instead of the device’s specialized hardware random number generator. Consequently, certain seed phrases became susceptible to being reconstructed by unauthorized parties.
Coinkite, the creator of Coldcard, has since released a firmware patch, though assets already compromised under the legacy seed phrases continue to remain vulnerable regardless of the update.
Thorn noted that a portion of the digital assets removed from impacted wallets were not stolen by criminal entities, but rather by whitehats, who are ethical security experts leveraging their technical abilities to discover and resolve security flaws.
These benevolent actors gathered the capital expressly to safeguard them until they could be successfully restored to their owners.
The 52.37 BTC shifted this week reflects one of these rescue operations, compiled from Wave 2 of the monitored breach funds alongside three specific footprints designated as AA, AU, and AX, and delivered to a destination address containing an OP_RETURN directive stating "claim:cryptorecoverytrust dot com." The transfer was verified within block 967,948.
Thorn explained that this volume represents 2.8% of the aggregate tracked breach funds and that approximately 40% of Wave 2 has now been identified as whitehat intervention. An additional 3.0134 BTC lacking any prior tracking background also entered the CRT destination address during the exact same transfer. Thorn mentioned that this is presumably extra Coldcard funds recovered by ethical hackers, although he emphasized that this detail is still unverified.
Affected individuals can verify whether their assets were part of those rescued by navigating to cryptorecoverytrust.com and looking up their wallet addresses.
Originally published at https://www.coindesk.com/markets/2026/09/22/whitehats-move-52-bitcoin-from-the-coldcard-hack-to-a-recovery-trust.