Hack Coldcard: 52 BTC Saved by Ethical Hackers
Finally, some good news in the Coldcard case. Nearly two months after the Coldcard breach that siphoned off over 1,800 BTC from wallets deemed unhackable, 52.37 bitcoins have now taken the opposite route. They are now resting in a legal trust in Wyoming tasked with returning them to their owners. The stash weighs in at about $4.5 million at current rates. However, one must knock on the right door without falling into a new trap.
Key Points:
- On September 21, white hats gathered 52.37 BTC linked to the hack on an address of the Crypto Recovery Trust.
- According to Galaxy Research, nearly 40% of the funds from the second wave were seized by security researchers, not thieves.
- Victims prove they control their address by signing a message, without ever revealing their recovery phrase.
- Updating your Coldcard does not protect a seed created with the old firmware.
Hack Coldcard: The Hackers Were Not Alone in the Scheme
Back to July 30. In 25 minutes, 594 BTC left about 500 Coldcard addresses. The cause? A firmware flaw caused the seeds (the recovery phrase that grants access to the funds) to be generated from a software randomness source that was far too predictable instead of the dedicated chip, making the keys guessable through brute force. Subsequent waves brought the total to around 1,830 BTC according to Galaxy Research.
However, not everyone was emptying these addresses for the same purpose. According to Alex Thorn, head of research at Galaxy, quoted by CoinDesk on September 22, about 40% of the bitcoins from the second wave were swept up by ethical hackers. These white hats exploit the flaw before the criminals to secure the funds.
The transfer on September 21, confirmed in block 967,948, gathers 30.19 BTC from this second wave, 17.98 BTC from a group of addresses called AX, and a few crumbs from two others. Approximately 3 BTC with no known history were also added, which Thorn attributes to other Coldcard rescues without being able to confirm. All of this landed on an address marked with an OP_RETURN message, a text inscription engraved in the blockchain, which points to cryptorecoverytrust.com.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948
these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ
--- Alex Thorn (@intangiblecoins) September 21, 2026
Who Holds the Keys to the Coldcard Bitcoins Vault
First instinct, distrust. An address that invites you to "claim" lost funds looks exactly like the scams targeting hacking victims. On paper, however, this setup holds up. The Crypto Recovery Trust is a statutory trust in Wyoming (Recovered Digital Asset Statutory Trust of Wyoming) whose trustee is the company Agentic Trace LLC. Lawyers from the national security division of the Steptoe firm advise it. DART, a structure specialized in digital asset recovery, coordinated the rescues and had already claimed "a little over 50 BTC" secured by August 17.
No one will ask you for your seed. DART makes it clear in black and white: no recovery phrase, no private key, no PIN code, only addresses and transaction identifiers. To prove that he controls an address, the requester signs a unique message with keys that never leave his home. The trust then verifies ownership and the origin of the funds and screens the requesters against sanction lists before any restitution. The site also assures that it does not charge any fees.
Victims of the Coldcard Hack: Good Reflexes Before Claiming
If your bitcoins disappeared between the end of July and the end of August, type the website address yourself rather than clicking on a link received by message or email, then search for your addresses in the trust's database. Fake recovery services spring up like mushrooms after every hack, and this one will be no exception. A request for a recovery phrase or "unlocking fees" is a sure sign of fraud.
Another, more insidious trap. Many holders believe they are in the clear because their Coldcard is running with the latest firmware. Coinkite has hammered this point: an update does not fix a seed generated by the faulty version. If yours was created on a Mk2 or Mk3 before the fix, you need to generate a new one and transfer your funds, whether your coins were targeted or not.
These 52.37 BTC only represent about 2.8% of the loot recorded by Galaxy. By the end of August, 87% of the stolen bitcoins had still not left the hackers' addresses, and every vulnerable Coldcard seed still in service remains a target, for both thieves and white hats.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

26 Companies Including Toshiba Join Japan's Blockchain-Based Stablecoin EJPY Pilot

White House Teleprompter Operator Profits $107,500 from Contract Trading, CFTC Warns of Manipulation Risks

Tether says EQIBank exposure below 0.034% after U.S. seizure

Hive Appeals to European Commission Over Swedish Bitcoin Mining VAT Dispute

Robinhood: Tenev Sees Crypto Outpacing Sports

Bitget Wallet Confirms User Asset Security, Spot ETF Net Inflow Reaches $191 Million

Senate Democrats Request Public Hearing On Prediction Markets

Ondo launches BlackRock portfolio tokens for non-US investors

Robinhood Chain Achieves $1.5 Billion in DEX Trading Volume and $114 Million in Fees in August

Two obscure pools fuel 2.8B XRPL volume, but only 185 trades caused it

Compute Finance: The Financial Layer Being Built by the AI Economy, 0G is Constructing a New Paradigm for Computing Assets

SkyAI Reelects Five Directors, Equity Incentive Plan Rejected

The Illusion of $1 Billion in Trading Volume? Testing the Real Selling Pressure of Coinbase Stock Tokens During U.S. Market Closure
![[Column] The On-Chain Transformation of Financial Markets Accelerated by the U.S.](/public-static/030_efb4e908c1.png?format=avif)
[Column] The On-Chain Transformation of Financial Markets Accelerated by the U.S.

Wall Street Legend Bill Miller: Why Did I Bet Half My Fortune on Bitcoin?

Lightning Labs reveals bug allowing canceled invoices to appear paid

Hyperliquid and Phantom Submit Comment Letter Advocating That Protocol Developers Should Not Be Considered Financial Intermediaries

The Stronger the AI, the Lower the Wages: Your Education is Becoming the Most Expensive Devalued Asset

Fed proposes GENIUS Act rules for stablecoin reserves and bank issuers

xStocks adds Ledger hardware wallet support for tokenized shares

European Regulators Warn of Quantum Risk by 2030

SEC Grants Five-Year Exemption for Tokenized US Stocks, Synthetic Exposure Products Excluded

Brazil Surpasses the U.S. in Cryptocurrency Adoption, Moves $252.5 Billion

Strive raises $86M through SATA as Bitcoin treasury buying continues

The EU will strengthen its oversight of AI and tokenization starting in 2027

ViaBTC Partners with Mempool to Expand Access to BTC Transaction Acceleration Services

ARK Invest Launches Venture Fund on Ethereum with Minimum Investment of $500

NYSE is assembling the pipes for a $5.5 trillion tokenized asset market

Crypto in France: Binance, taxes, digital euro, what changes by 2027








