Crypto news report · source clearly identified
White Hats Recover 52.37 BTC from Coldcard Exploit
A group of white hats secured 52.37 BTC, about 2.8% of the funds affected by the Coldcard vulnerability, and moved them to a Crypto Recovery Trust address.

Researchers from Galaxy Digital identified a coordinated effort by white‑hat actors to intercept Bitcoin stolen in the Coldcard hardware‑wallet exploit. The group moved 52.37 BTC to an address controlled by Crypto Recovery Trust, a Wyoming‑based entity created to return rescued assets to their rightful owners.
White‑hat sweep of Wave 2 funds
Galaxy Digital’s head of firm‑wide research, Alex Thorn, traced the transaction to block 967,948. The on‑chain data included an OP_RETURN field reading “claim:cryptorecoverytrust dot com,” indicating the destination of the rescued coins. Thorn estimates the 52.37 BTC represent roughly 2.8 % of the total Coldcard‑related theft and about 40 % of the “Wave 2” batch of transactions.
Scope of the rescue
The rescued amount is valued at over $4.4 million at current prices. Thorn also observed an additional 3.0134 BTC in the same transaction, but its origin remains unconfirmed.
Remaining stolen funds
Overall, the Coldcard exploit affected more than 8,600 addresses and approximately 1,779 BTC. Thorn’s accounting of Waves 1, 2, and 3, together with the recovered funds, covers 1,393 BTC (about 76 % of the reported total). Wave 1 (1,082.57 BTC) and Wave 3 (116.98 BTC) remain untouched, while a portion of Wave 2 (about 60 %) is still unaccounted for and may have been taken by malicious actors or other white‑hat groups.
Challenges in returning the Bitcoin
Crypto Recovery Trust must verify ownership before returning the coins. Thorn suggests a multi‑factor approach, including device forensics, exchange KYC records, victim‑provided extended public keys, and early FBI reports. The trust also offers a search tool for victims to check whether their addresses are included in the rescued batch.
Technical cause of the exploit
The underlying vulnerability was a firmware bug in Coldcard wallets that weakened seed generation, allowing attackers to reconstruct seeds offline. The issue was first observed on July 30, 2026, and led to the rapid disappearance of Bitcoin from vulnerable wallets during the summer.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- September 22, 2026, 9:41 PM
- Original headline
- White Hats Beat Coldcard Attackers, Rescuing Millions of Dollars in Bitcoin