Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust
According to Galaxy Digital, the good guys have moved 52 BTC to an address carrying an OP_RETURN message reading “claim:cryptorecoverytrust dot com.”
- White-hat hackers moved 52.37 Bitcoin linked to the July Coldcard wallet exploit into an address associated with a newly formed recovery trust.
- The exploit, which caused more than $100 million in estimated losses, used weak software-based randomness to generate wallet seeds that attackers could reconstruct.
- Victims can search their wallet addresses at cryptorecoverytrust.com to determine whether the ethical hackers recovered their funds.
.
Attackers exploited this, causing wallets to generate seeds using a weaker software-based random number source instead of the wallet’s dedicated random number generator. That made some seeds vulnerable to reconstruction by hackers.
Coinkite, the maker of Coldcard, has since patched the firmware, though funds already exposed under the old seeds remain at risk regardless of the patch.
Read More: Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
According to Thorn, some of the coins moved out of victim wallets weren’t taken by malicious actors but by whitehats, or ethical cybersecurity professionals who use hacking skills to find and fix security weaknesses.
These so-called good guys swept the funds specifically to keep them safe until they could be returned.

