Hack Coldcard: 52 BTC Saved by Ethical Hackers
Finally, some good news in the Coldcard case. Nearly two months after the Coldcard breach that siphoned off over 1,800 BTC from wallets deemed unhackable, 52.37 bitcoins have now taken the opposite route. They are now resting in a legal trust in Wyoming tasked with returning them to their owners. The stash weighs in at about $4.5 million at current rates. However, one must knock on the right door without falling into a new trap.
Key Points:
- On September 21, white hats gathered 52.37 BTC linked to the hack on an address of the Crypto Recovery Trust.
- According to Galaxy Research, nearly 40% of the funds from the second wave were seized by security researchers, not thieves.
- Victims prove they control their address by signing a message, without ever revealing their recovery phrase.
- Updating your Coldcard does not protect a seed created with the old firmware.
Hack Coldcard: The Hackers Were Not Alone in the Scheme
Back to July 30. In 25 minutes, 594 BTC left about 500 Coldcard addresses. The cause? A firmware flaw caused the seeds (the recovery phrase that grants access to the funds) to be generated from a software randomness source that was far too predictable instead of the dedicated chip, making the keys guessable through brute force. Subsequent waves brought the total to around 1,830 BTC according to Galaxy Research.
However, not everyone was emptying these addresses for the same purpose. According to Alex Thorn, head of research at Galaxy, quoted by CoinDesk on September 22, about 40% of the bitcoins from the second wave were swept up by ethical hackers. These white hats exploit the flaw before the criminals to secure the funds.
The transfer on September 21, confirmed in block 967,948, gathers 30.19 BTC from this second wave, 17.98 BTC from a group of addresses called AX, and a few crumbs from two others. Approximately 3 BTC with no known history were also added, which Thorn attributes to other Coldcard rescues without being able to confirm. All of this landed on an address marked with an OP_RETURN message, a text inscription engraved in the blockchain, which points to cryptorecoverytrust.com.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948
these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ
--- Alex Thorn (@intangiblecoins) September 21, 2026
Who Holds the Keys to the Coldcard Bitcoins Vault
First instinct, distrust. An address that invites you to "claim" lost funds looks exactly like the scams targeting hacking victims. On paper, however, this setup holds up. The Crypto Recovery Trust is a statutory trust in Wyoming (Recovered Digital Asset Statutory Trust of Wyoming) whose trustee is the company Agentic Trace LLC. Lawyers from the national security division of the Steptoe firm advise it. DART, a structure specialized in digital asset recovery, coordinated the rescues and had already claimed "a little over 50 BTC" secured by August 17.
No one will ask you for your seed. DART makes it clear in black and white: no recovery phrase, no private key, no PIN code, only addresses and transaction identifiers. To prove that he controls an address, the requester signs a unique message with keys that never leave his home. The trust then verifies ownership and the origin of the funds and screens the requesters against sanction lists before any restitution. The site also assures that it does not charge any fees.
Victims of the Coldcard Hack: Good Reflexes Before Claiming
If your bitcoins disappeared between the end of July and the end of August, type the website address yourself rather than clicking on a link received by message or email, then search for your addresses in the trust's database. Fake recovery services spring up like mushrooms after every hack, and this one will be no exception. A request for a recovery phrase or "unlocking fees" is a sure sign of fraud.
Another, more insidious trap. Many holders believe they are in the clear because their Coldcard is running with the latest firmware. Coinkite has hammered this point: an update does not fix a seed generated by the faulty version. If yours was created on a Mk2 or Mk3 before the fix, you need to generate a new one and transfer your funds, whether your coins were targeted or not.
These 52.37 BTC only represent about 2.8% of the loot recorded by Galaxy. By the end of August, 87% of the stolen bitcoins had still not left the hackers' addresses, and every vulnerable Coldcard seed still in service remains a target, for both thieves and white hats.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Nearly $20 million in XRP drained from 6,678 wallets across six attack waves

Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens

Yield Curve Approaches Inversion, TGA and Fed Tools Become New Focus in US Treasury Market

Brevo Hacking: After Trezor, Paymium Customer Data Leaked

Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

NVDA Stock Rose for a Fifth Straight Day: Jensen Huang Says Sales Will Double Next Year

WEEX P2P now supports XOF, XAF & CDF—Merchant Recruitment Now Open

EURC scam: Dutch police arrest 2 over fake Rolex deals

What is Fast? Understanding the Parallel Payment Infrastructure for AI Agents

Elon Musk’s X adds Bitcoin trading links for U.S. users

Robinhood CEO Says Crypto Will Beat Sports at Prediction Markets' Own Game

ZEC's Largest Mining Company Moves to US Stock Market After Mining 70,000 ZEC in Six Months

U.S. Banks Face $326.7 Billion in Unrealized Losses

MU Stock Retail Sentiment Just Turned Sour: The CEO Sold Shares Right Before Earnings
MU retail sentiment is souring ahead of September 30 earnings, and the CEO just sold $39 million in shares but the sale traces back to a plan set eight months ago.

Cardano x402: the official integration that allows AI agents to pay APIs in ADA

SEC Takes Action: Who Can Handle "Compliant ICOs"?

Circle wants you to love USDC a little like you love Chelsea

Ethereum and Base Abandon Common Standard for Crypto Wallets

Cryptocurrency Security Guide: How to Identify and Prevent Social Engineering Attacks

Your crypto hardware wallet can stay secure while everything around it fails

How to Spend Crypto on Apple Pay in 2026 (No Selling)

Neutrl opens NUSD redemptions as contract reads 0.51

World Money launches in 150+ countries with Stripe

What Are the Conditions for Success of Data Centers? A Map of AI Data Centers in Korea – Bitplanet

Bottomline Chooses Chainlink to Bring On-Chain Payments to 600 Banks

Why Is Bitcoin Reacting to the September 2026 Fed Rate Hike?
Why did Bitcoin hold near $76,000 after the September 2026 Fed rate hike? See how expectations, yields, the dollar, and liquidity shaped BTC.

Crypto Futures on Moscow Exchange: Already 600 Billion Rubles Traded

The Fed Hikes Rates 25 Basis Points to 3.75%–4% — Here's What It Means for Bitcoin's Next Move
Kevin Warsh's inflation warning, a more hawkish dot plot, and three roads ahead for crypto

Fed Rate Hike 2026: Can Bitcoin Hold $75K as Gold Stays Strong?









