Crypto news report · source clearly identified

White hats recover 52 Bitcoin from Coldcard exploit, and a new public portal lets victims check eligibility

A Sept. 21 transaction points owners toward a trust address check for an earlier disclosed rescue, with any return subject to verification.

Researchers have identified a Bitcoin transaction that may allow owners of compromised Coldcard hardware wallets to verify whether their funds were part of a recent white‑hat recovery.

Transaction details and public check

Galaxy researcher Alex Thorn linked a transaction on September 21, recorded in block 967,948, to a Crypto Recovery Trust. The transaction references approximately 52.37 BTC that originated from clusters associated with the Coldcard exploit.

Thorn advises affected users to enter their public Bitcoin address on the trust’s website. A matching address can initiate a claim process, but the verification step requires proof of ownership and does not involve sharing seed phrases or private keys.

Scope of the recovered funds

  • The 52.37 BTC represents about 2.8 % of the total funds tracked by Galaxy as related to the Coldcard breach.
  • An additional 3.0134 BTC moved to the same destination from addresses not previously linked to the exploit, which may indicate further white‑hat recoveries.

Background on the recovery effort

In an August 17 report, digital‑asset recovery firm DART disclosed that it, together with independent researchers, had secured just over 50 BTC and placed the coins with the Crypto Recovery Trust. The September 21 transaction provides a public trail for that earlier rescue.

Claim verification process

DART’s trust process includes checks of recovery records, chain of custody, and proof of ownership, such as source‑of‑funds documentation and exchange transaction history. Potential sanctions, competing claims, or other restrictions may affect any payout.

Coldcard vulnerability reminder

The underlying issue stems from a flaw in Coldcard seed generation that allowed attackers to reconstruct private keys from certain firmware versions. DART notes that wallets created with the affected firmware remain vulnerable even after updates, and owners should follow the manufacturer’s migration guidance.

Users are warned not to submit seeds, private keys, PINs, or recovery codes through any web form. The public address check is the only information required to start the eligibility verification.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 24, 2026, 1:10 AM
Original headline
White hats recover 52 Bitcoin from Coldcard exploit, and a new public portal lets victims check eligibility
View original report ↗