Key Takeaways
White-hat hackers moved 52.37 BTC linked to the Coldcard exploit into a Wyoming-based recovery trust.
The trust will work to identify rightful owners and return the recovered bitcoin, though proving ownership may be challenging.
Researchers say significant amounts of bitcoin linked to the exploit remain untouched or have moved through other channels.
Recovered Bitcoin Moved to Secure Custody
White-hat hackers have moved 52.37 bitcoin taken from wallets affected by the Coldcard exploit into a recovery trust, in an effort to keep the funds safe and eventually return them to their owners.
The bitcoin was moved to an address controlled by Crypto Recovery Trust, a Wyoming-based trust created to help return the digital assets recovered by security researchers.
The 52.37 BTC is worth more than $4 million at recent prices and represents about 2.8% of the total bitcoin linked to the Coldcard exploit.
Galaxy Digital head of research Alex Thorn identified the transfer and reported it on X.
“COLDCARD WHITE HAT MOVES FUNDS TO TRUST,” Thorn wrote.
According to Thorn, the 52.37 BTC came from several groups of addresses linked to the Coldcard incident, including part of what researchers call “Wave 2” and addresses labeled AA, AU and AX.

The graph shared by Alex Thorn on X (Click for larger image)
The transaction was confirmed in Bitcoin block 967,948. It also included an OP_RETURN message reading “claim:cryptorecoverytrust dot com,” apparently pointing victims toward the recovery trust.
The Coldcard incident began in late July after researchers discovered that a vulnerability in certain Coldcard firmware could make some Bitcoin wallets vulnerable.
The problem involved how wallet seeds were generated. Instead of always using the device's hardware-based random number generator, affected versions could fall back to a weaker software-based random number generator.
A Bitcoin wallet's seed is extremely important because it is used to generate the private keys that control the wallet. If an attacker can predict or reconstruct the seed, they may be able to take the bitcoin.
Once the vulnerability became known, attackers began moving funds from affected wallets. But it was not only criminals who were watching the vulnerable wallets.
White-hat hackers also identified some of the exposed bitcoin and moved it before attackers could get there. Their goal was to protect the coins rather than steal them.
Thorn said about 40% of the bitcoin associated with Wave 2 appears to have been moved by white hats. Those funds have now apparently been sent to Crypto Recovery Trust.
Security researcher Nick Bax previously confirmed that he helped with the operation.
“Finally able to say that at the end of July, I was involved in the rescue of ~50 BTC which were imminently going to be stolen due to the COLDCARD entropy flaw,” Bax wrote on X.
He said the funds were being held by a Wyoming trust so they could be returned to their rightful owners.
The 52.37 BTC may not be the only recovered bitcoin that reached the trust. Thorn said an additional 3.0134 BTC was sent to the same address during the transaction. Galaxy Digital had not previously tracked those coins, however.
Thorn said they were “presumably” additional Coldcard funds recovered by white hats, but said there was not enough evidence to confirm their origin.
Galaxy has been tracking the Coldcard exploit and has identified several groups of transactions connected to the attack.
According to Thorn, waves 1, 2 and 3, together with the bitcoin sent to the recovery trust, account for about 1,393 BTC, or 76.1% of the published total of exploited funds.
Of the stolen funds, wave 1 still has 1,082.57 BTC untouched. In wave 3, 116.98 BTC remains untouched, while 97.09 BTC was moved through coinjoin or routed through Thorchain to Ethereum before being sent through Tornado Cash.

Graph showing BTC stolen in the Coldcard hack. Green indicates BTC sent to Trust; the remaining funds are still under the hackers’ control (Click for larger image) — Alex Thorn on X
Galaxy has also identified addresses labeled AA, AU and AX as 100% white-hat activity.
There is still uncertainty around the remaining 60% of wave 2. Researchers do not yet know whether those funds were moved by criminals or by another group of white-hat hackers.
Thorn said the remaining funds appear to have been handled by a different operator or group of operators than the bitcoin that was sent to Crypto Recovery Trust.
Recovering the bitcoin is only part of the problem. The trust also needs to determine who actually owned the funds before they were moved. That could be difficult because the same wallet credentials may be available to both the original owner and anyone who obtained the compromised seed.
Kevin Loaec, CEO of WizardSardine, weighed in on the conversation, arguing that this amounts to stealing rather than a typical white-hat move. He said proving ownership of the funds is essentially impossible, meaning many victims may never get their coins back.

Kevin Loaec on X
This remains a pivotal part of the conversation, as many users question how ownership can be established when the seed phrase is known to both the rightful owner and the hackers.
X user “gvictor808” raised the same question, prompting Thorn to offer several possible answers. According to Thorn, ownership can be established through various forms of evidence, including device forensics, exchange KYC records, and records of reports filed with the FBI.
For now, the 52.37 BTC moved by white hats is being held by the recovery trust. The next step is identifying the rightful owners and returning the Bitcoin to them.
The recovery effort does not resolve the entire Coldcard exploit, but it means that at least some bitcoin that was at risk of being stolen by attackers was intercepted and placed in protective custody instead.





