Whitehats Move 52.37 BTC After Coldcard Hack
The move follows the July Coldcard exploit, where a flaw in the hardware wallet exposed seeds. Coinkite has patched the firmware, but old addresses remain vulnerable.

Key Takeaways
- Whitehat operators moved 52.37 BTC to a newly created recovery trust address after the July Coldcard hack.
- The transaction bundled coins from Wave 2 and three traces; according to Alex Thorn, this is 2.8% of the tracked exploit funds.
- The Coldcard hack was caused by a weak source of randomness, which allowed seeds to be reconstructed and left funds vulnerable.
Whitehat operators have moved 52.37 BTC to an address tied to a newly created recovery trust. The transaction is linked to the aftermath of the Coldcard hack in July, when attackers took advantage of a flaw in the hardware wallet and were able to expose large amounts of bitcoin.
What Has Been Moved Now
According to Galaxy Digital executive Alex Thorn, these are coins that were not taken by bad actors, but secured by whitehats. The 52.37 BTC were combined this week from Wave 2 of the tracked exploit funds, along with three traces labeled AA, AU, and AX. They were sent to an address with an OP_RETURN message that says: claim:cryptorecoverytrust dot com.
The transaction was confirmed in block 967.948. Thorn said this is 2.8% of the total tracked exploit funds. He added that about 40% of Wave 2 has now been identified as whitehat activity. In the same transaction, another 3.0134 BTC with no prior tracking history also flowed to the CRT address. According to Thorn, this is likely extra recovered Coldcard funds, but that has not been confirmed yet.
Background on the Hack
The Coldcard hack started on July 30 and then continued in multiple waves. Attackers managed to get seeds generated through a weaker software-based source of random numbers, instead of the wallet's own random number generator. That allowed some seeds to be reconstructed later.
Coinkite, the maker of Coldcard, has since patched the firmware. Still, funds that were already exposed under the old seeds remain vulnerable, even after that update. According to the initial estimates, more than $100 million (€87 million) in bitcoin was involved. Broader estimates around the exploit put the total at about 1,816 BTC spread across more than 5,200 addresses, showing how wide the impact of the flaw was.
Why This Matters
The case shows how quickly a self-custody mistake can ripple through the crypto market. After the exploit, on-chain activity jumped sharply as more users moved funds to centralized custodians or multisig setups. For European crypto readers, that matters especially because hardware wallets are often seen as a basic layer for self-management, while this case shows how important good entropy and secure storage really are. Coldcard's firmware update also already highlighted how big the impact of the vulnerability was.