
White hat researchers secure 52 Bitcoin from Coldcard exploit
- Independent cybersecurity researchers successfully rescued 52.37 Bitcoin from compromised digital wallets following a major security flaw in Coldcard hardware signing devices.
- The intercepted funds represent approximately 2.8% of the tracked assets linked to the exploit and have been transferred into a specialised recovery vehicle.
- The operation establishes a legal path for verified victims to reclaim stolen assets through formal ownership verification protocols.
White hat security operators have outrun malicious hackers to evacuate 52.37 Bitcoin (BTC) from compromised digital wallet addresses exposed by a critical hardware vulnerability.
The intervention targeted addresses vulnerable to an entropy flaw in certain Coldcard firmware builds, which allowed attackers to reconstruct wallet seed phrases offline.
"52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN 'claim:cryptorecoverytrust dot com' in block 967,948," according to Galaxy Digital Holdings Ltd (TSE:GLXY) Head of Firmwide Research Alex Thorn.
The targeted firmware bug compromised over 8,600 wallet addresses and exposed roughly 1,779 Bitcoin to potential theft since late July.
"We now know that ~40% of Wave 2 was actually white hats sweeping coins to protect victim funds," according to Head of Firmwide Research Alex Thorn.
The rescued capital has been deposited into the Crypto Recovery Trust, a Wyoming statutory entity established to manage and distribute reclaimed digital assets.
Affected users can submit extended public keys and device forensic logs through the trust to prove ownership and initiate asset returns.
Following the update, Bitcoin (BTC) was trading at $86,469.06.



