White-hat hackers recover 52.37 BTC from Coldcard exploit through Crypto Recovery Trust

Why it matters
This incident highlights the ongoing vulnerabilities in cryptocurrency hardware and the importance of recovery mechanisms for investors.
What happened (in 30 seconds)
- On September 21, 2026, white-hat operators rescued 52.37 BTC from a Coldcard exploit, preventing further theft.
- The funds represent 2.8% of the total exploited Bitcoin, valued at approximately $4.4 million.
- Crypto Recovery Trust now manages the funds for verified victim restitution, with a claims portal active for ownership verification.
The context you actually need
- Coldcard devices suffered from a firmware vulnerability that allowed seed reconstruction, leading to significant losses.
- Over 1,700 BTC was lost due to this exploit, affecting thousands of users and raising concerns about hardware security.
- White-hat hackers have become crucial in mitigating losses and restoring trust in the cryptocurrency ecosystem.
What's really happening
The Coldcard exploit originated from a firmware error in March 2021, which caused certain Mk2 and Mk3 devices to generate wallet seeds with reduced entropy. This vulnerability relied on a predictable software pseudo-random number generator instead of hardware randomness, making it easier for attackers to reconstruct wallet seeds offline. By July 30, 2026, malicious actors began exploiting this weakness, draining vulnerable wallets in multiple waves and leading to confirmed losses of approximately 1,779 BTC across more than 8,600 addresses.
On September 21, 2026, Galaxy researcher Alex Thorn identified on-chain movements indicating that 52.37 BTC from the exploit was consolidated into a new address controlled by Crypto Recovery Trust. This action was part of a broader effort by white-hat researchers, including Nick Bax and DART researchers, who had previously secured over 50 BTC by late July 2026 to preempt further theft. The funds were moved without claiming a bounty, reflecting a commitment to victim restitution rather than personal gain.
The successful recovery of these funds represents a significant achievement in the ongoing battle against cryptocurrency theft. Approximately 40% of the Wave 2 clusters tracked by Galaxy Research are now attributed to protective white-hat activity, while the status of the remaining 60% remains uncertain. The Crypto Recovery Trust is now tasked with managing ownership verification through device forensics, KYC records, and other evidence to ensure that the funds are returned to legitimate owners.
This incident underscores the importance of robust recovery mechanisms in the cryptocurrency space. As more users adopt digital assets, the need for secure hardware and effective recovery solutions becomes increasingly critical. The establishment of a public claims portal at cryptorecoverytrust.com allows victims to check their eligibility for recovery, fostering a sense of accountability and transparency in the aftermath of the exploit.
Who feels it first (and how)
- Cryptocurrency holders: Increased awareness of hardware vulnerabilities and recovery options.
- Investors: Heightened scrutiny on security measures and trust in recovery operations.
- Crypto Recovery Trust: Gaining prominence as a key player in asset recovery and victim support.
- White-hat hackers: Recognition and potential for increased collaboration in future recovery efforts.
What to watch next
- Victim restitution progress: Monitoring how effectively Crypto Recovery Trust returns funds to verified owners will indicate the trust's operational efficiency.
- Future exploits: Keeping an eye on emerging vulnerabilities in cryptocurrency hardware could signal the need for enhanced security measures.
- Market response: Observing any shifts in Bitcoin market prices or regulatory actions following this incident will provide insights into investor sentiment and confidence.
The Coldcard exploit resulted in significant losses, with over 1,700 BTC drained from wallets.
Increased focus on hardware security and recovery solutions in the cryptocurrency market.
The status of the remaining 60% of exploited funds and whether further recoveries will occur.
Frequently Asked Questions
- Why it matters?
- This incident highlights the ongoing vulnerabilities in cryptocurrency hardware and the importance of recovery mechanisms for investors.
- What happened (in 30 seconds)?
- On September 21, 2026, white-hat operators rescued 52.37 BTC from a Coldcard exploit, preventing further theft. The funds represent 2.8% of the total exploited Bitcoin, valued at approximately $4.4 million. Crypto Recovery Trust now manages the funds for verified victim restitution, with a claims portal active for ownership verification.
- What's really happening?
- The Coldcard exploit originated from a firmware error in March 2021, which caused certain Mk2 and Mk3 devices to generate wallet seeds with reduced entropy. This vulnerability relied on a predictable software pseudo-random number generator instead of hardware randomness, making it easier for attackers to reconstruct wallet seeds offline. By July 30, 2026, malicious actors began exploiting this weakness, draining vulnerable wallets in multiple waves and leading to confirmed losses of approximatel
- Who feels it first (and how)?
- Cryptocurrency holders: Increased awareness of hardware vulnerabilities and recovery options. Investors: Heightened scrutiny on security measures and trust in recovery operations. Crypto Recovery Trust: Gaining prominence as a key player in asset recovery and victim support. White-hat hackers: Recognition and potential for increased collaboration in future recovery efforts.
- What to watch next?
- Victim restitution progress: Monitoring how effectively Crypto Recovery Trust returns funds to verified owners will indicate the trust's operational efficiency. Future exploits: Keeping an eye on emerging vulnerabilities in cryptocurrency hardware could signal the need for enhanced security measures. Market response: Observing any shifts in Bitcoin market prices or regulatory actions following this incident will provide insights into investor sentiment and confidence.
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
White Hats Beat Coldcard Attackers, Rescuing Millions of Dollars in Bitcoin
White hat hackers successfully intervened in a significant security breach involving Coldcard hardware wallets, managing to rescue 52 Bitcoin, valued at millions of dollars, from the attackers. This operation underscores the ongoing battle between et...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
White hats outrun Coldcard hackers in 52-Bitcoin evacuation
White hat hackers successfully secured approximately 40% of the Bitcoin involved in the Coldcard exploit's second wave, transferring the funds to a Wyoming trust designated for victims. This operation highlights the ongoing battle between ethical hac...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Coldcard whitehats move 52.37 BTC to recovery trust
White hat hackers associated with Coldcard successfully transferred 52.37 BTC from wallets linked to a recent exploit into a recovery trust, which will verify claims from affected owners. This operation highlights the proactive measures taken to secu...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust
White hat hackers have successfully moved 52 Bitcoin from the Coldcard hack to a recovery trust, as reported by Galaxy Digital. This transfer includes an OP_RETURN message directing to a recovery website, indicating a proactive approach to securing f...