Loading prices…
🩸BEARISH

Coldcard Exploit Whitehats Move 52 BTC to Recovery Trust

The transfer offers a recovery path after a wallet-seed flaw exposed more than $100M, but funds under the old randomness remain at risk despite Coldcard’s firmware patch.

Coldcard Exploit Whitehats Move 52 BTC to Recovery Trust
Coldcard Exploit Whitehats Move 52 BTC to Recovery Trust
Coldcard Exploit Whitehats Move 52 BTC to Recovery Trust
Coldcard Exploit Whitehats Move 52 BTC to Recovery Trust

Whitehat operators moved 52.37 BTC linked to the July Coldcard wallet exploit into an address associated with a newly formed recovery trust, Galaxy Digital research chief Alex Thorn said. The transaction consolidated funds from Wave 2 and three tracked exploit footprints, and was confirmed in block 967,948. The receiving address carried an OP_RETURN message directing victims to the recovery trust.

Why it matters

The Coldcard exploit began on July 30 and caused estimated losses of more than $100 million across multiple attack waves. The vulnerability involved weak software-based randomness used to generate wallet seeds instead of the device’s dedicated random number generator, leaving some seeds vulnerable to reconstruction.

Coinkite has patched the firmware, but the fix does not protect funds generated under the old process. Whitehat operators have swept some exposed coins to keep them secure while victims seek their return, complicating the distinction between malicious theft and recovery activity.

Market impact

The 52.37 BTC transfer represents 2.8% of the total tracked exploit funds. Thorn said roughly 40% of Wave 2 has now been identified as whitehat activity, giving affected users a clearer path to determine whether their funds were recovered.

An additional 3.0134 BTC entered the recovery trust address in the same transaction. Thorn said it was presumably recovered Coldcard funds, but that attribution remains unconfirmed. Victims can search their wallet addresses through the recovery trust’s website.

Related tokens
$BTC

Frequently asked questions

  1. How much Bitcoin did whitehat operators move into the recovery trust?

    Whitehat operators moved 52.37 BTC linked to the Coldcard exploit into an address associated with the recovery trust.

  2. What caused the Coldcard wallet exploit?

    The exploit involved weak software-based randomness used to generate wallet seeds instead of the device’s dedicated random number generator. Some affected seeds could be reconstructed.

  3. Does Coldcard’s firmware patch protect funds generated under the old process?

    No. The patch addresses the vulnerability, but funds generated under the old randomness remain exposed if they were already affected.

  4. How much of Wave 2 has been identified as whitehat activity?

    Galaxy Digital’s Alex Thorn said roughly 40% of Wave 2 has now been identified as whitehat activity.

  5. What is the status of the additional 3.0134 BTC sent to the trust?

    The 3.0134 BTC entered the recovery trust address in the same transaction, but its connection to recovered Coldcard funds remains unconfirmed.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 54m ago
Open original →