According to Galaxy Digital, the good guys have moved 52 BTC to an address carrying an OP_RETURN message reading "claim:cryptorecoverytrust dot com."

  • White-hat hackers moved 52.37 Bitcoin linked to the July Coldcard wallet exploit into an address associated with a newly formed recovery trust.
  • The exploit, which caused more than $100 million in estimated losses, used weak software-based randomness to generate wallet seeds that attackers could reconstruct.
  • Victims can search their wallet addresses at cryptorecoverytrust.com to determine whether the ethical hackers recovered their funds.

“Whitehat operators” have moved 52.37 BTC to an address linked to a newly formed recovery trust, as part of the ongoing fallout from July's Coldcard hardware wallet exploit, according to Galaxy Digital's Head of Research Alex Thorn.

The Coldcard crypto hardware wallet hack began on July 30, with multiple batches (waves 1, 2, and 3) of attacks in subsequent days resulting in estimated losses of over $100 million in bitcoin

Attackers exploited this, causing wallets to generate seeds using a weaker software-based random number source instead of the wallet’s dedicated random number generator. That made some seeds vulnerable to reconstruction by hackers.

Coinkite, the maker of Coldcard, has since patched the firmware, though funds already exposed under the old seeds remain at risk regardless of the patch.

Read More: Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

According to Thorn, some of the coins moved out of victim wallets weren't taken by malicious actors but by whitehats, or ethical cybersecurity professionals who use hacking skills to find and fix security weaknesses.

These so-called good guys swept the funds specifically to keep them safe until they could be returned.

The 52.37 BTC moved this week represents such a sweep, consolidated from Wave 2 of the tracked exploit funds along with three footprints labeled AA, AU and AX, and sent to an address carrying an OP_RETURN message reading "claim:cryptorecoverytrust dot com." The transaction was confirmed in block 967,948.

Thorn said the amount represents 2.8% of the total tracked exploit funds and that roughly 40% of Wave 2 has now been identified as whitehat activity. An additional 3.0134 BTC with no prior tracking history also flowed into the CRT address in the same transaction. Thorn said this is presumably additional white-hat-recovered Coldcard funds, though he stressed this remains unconfirmed.

Victims can check whether their funds were among those recovered by visiting cryptorecoverytrust.com and searching their addresses.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.