Finst

Whitehats Move 52.37 BTC After Coldcard Hack

The move follows the July Coldcard exploit, where a flaw in the hardware wallet exposed seeds. Coinkite has patched the firmware, but old addresses remain vulnerable.

Whitehats Move 52.37 BTC After Coldcard Hack

Key Takeaways

  • Whitehat operators moved 52.37 BTC to a newly created recovery trust address after the July Coldcard hack.
  • The transaction bundled coins from Wave 2 and three traces; according to Alex Thorn, this is 2.8% of the tracked exploit funds.
  • The Coldcard hack was caused by a weak source of randomness, which allowed seeds to be reconstructed and left funds vulnerable.

Whitehat operators have moved 52.37 BTC to an address tied to a newly created recovery trust. The transaction is linked to the aftermath of the Coldcard hack in July, when attackers took advantage of a flaw in the hardware wallet and were able to expose large amounts of bitcoin.

What Has Been Moved Now

According to Galaxy Digital executive Alex Thorn, these are coins that were not taken by bad actors, but secured by whitehats. The 52.37 BTC were combined this week from Wave 2 of the tracked exploit funds, along with three traces labeled AA, AU, and AX. They were sent to an address with an OP_RETURN message that says: claim:cryptorecoverytrust dot com.

The transaction was confirmed in block 967.948. Thorn said this is 2.8% of the total tracked exploit funds. He added that about 40% of Wave 2 has now been identified as whitehat activity. In the same transaction, another 3.0134 BTC with no prior tracking history also flowed to the CRT address. According to Thorn, this is likely extra recovered Coldcard funds, but that has not been confirmed yet.

Background on the Hack

The Coldcard hack started on July 30 and then continued in multiple waves. Attackers managed to get seeds generated through a weaker software-based source of random numbers, instead of the wallet's own random number generator. That allowed some seeds to be reconstructed later.

Coinkite, the maker of Coldcard, has since patched the firmware. Still, funds that were already exposed under the old seeds remain vulnerable, even after that update. According to the initial estimates, more than $100 million (€87 million) in bitcoin was involved. Broader estimates around the exploit put the total at about 1,816 BTC spread across more than 5,200 addresses, showing how wide the impact of the flaw was.

Why This Matters

The case shows how quickly a self-custody mistake can ripple through the crypto market. After the exploit, on-chain activity jumped sharply as more users moved funds to centralized custodians or multisig setups. For European crypto readers, that matters especially because hardware wallets are often seen as a basic layer for self-management, while this case shows how important good entropy and secure storage really are. Coldcard's firmware update also already highlighted how big the impact of the vulnerability was.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.