White-hat hackers moved 52.37 Bitcoin linked to the July Coldcard hardware wallet exploit into an address tied to a newly formed recovery trust, according to Galaxy Digital.
The transaction, confirmed in block 967,948, carried an OP_RETURN message reading "claim:cryptorecoverytrust dot com," indicating that victims may file claims against the recovered funds through the website.
The Coldcard hack began on July 30, with attackers launching multiple waves of exploitation over subsequent days. They targeted wallets generating seeds using a weaker software-based random number generator instead of the device's dedicated hardware RNG, making certain seeds reconstructable. The exploit, which affected an estimated 4,500 addresses, has caused more than $100 million in losses at Bitcoin's price of $85,254.31.
Coinkite, the maker of Coldcard, released a firmware patch following the attack, though funds exposed under the compromised seeds remain at risk regardless of the update.
According to Galaxy Digital Head of Research Alex Thorn, the 52.37 BTC moved this week was swept by ethical cybersecurity professionals rather than malicious actors. The funds were consolidated from Wave 2 of the tracked exploit along with three footprints labeled AA, AU and AX, then sent to the recovery trust address to be held until they can be returned to victims.
Thorn said the amount represents 2.8% of total tracked exploit funds and that roughly 40% of Wave 2 has now been identified as white-hat activity. An additional 3.0134 BTC with no prior tracking history also flowed into the recovery address in the same transaction; Thorn described this as presumably additional recovered Coldcard funds but noted the origin remains unconfirmed.
Victims can determine whether their funds were among those recovered by searching their wallet addresses at cryptorecoverytrust.com.












