White Hats Move 52 Bitcoin Into Recovery Trust After COLDCARD Wallet Flaw
• September 22, 2026 7:25 am • CommentsThe safest Bitcoin in a hardware wallet can still become vulnerable when the randomness behind its private keys fails.
That is the problem a white-hat team says it faced after discovering funds exposed by a COLDCARD entropy flaw. Instead of waiting for attackers to finish the job, the researchers moved 52.37 Bitcoin into a Wyoming recovery trust built to return the money to its rightful owners.
The transfer is a rare piece of good news inside a much larger security failure. It also shows what coordinated on-chain incident response can accomplish when defenders know which wallets are exposed and can reach them first.
Cointelegraph reports that the 52.37 BTC was consolidated into an address controlled by Crypto Recovery Trust. The rescued coins represented about 40% of the Bitcoin connected to the exploit’s second wave.
Security researcher and SEAL 911 incident responder Nick Bax said he participated in the rescue at the end of July. In his account, roughly 50 BTC was in immediate danger because of the entropy flaw.
Finally able to say that at the end of July, I was involved in the rescue of ~50 BTC which were imminently going to be stolen due to the COLDCARD entropy flaw.
The funds are currently held by a Wyoming trust, which will ensure that funds are returned to their rightful owners.
— Nick Bax (@bax1337) September 9, 2026
The word “rescued” matters here. The funds were placed under the control of a trust with a claims process, creating a legal and operational path for affected owners to recover their Bitcoin.
That custody step also reduces the danger of a chaotic return process. Sending coins back without proving ownership could create a second security failure on top of the first.
Galaxy Digital research head Alex Thorn said the transaction combined coins associated with several tracked footprints from the second wave. An OP_RETURN message in the transaction pointed potential claimants toward the recovery trust.
Thorn’s figures put the broader scale in perspective. The published incident total covered 1,830 BTC across 9,162 addresses.
Against that total, the white-hatted 52.37 BTC represented about 2.8%.
❄️COLDCARD WHITE HAT MOVES FUNDS TO TRUST 🏳️
52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX consolidated into a fresh address with an OP_RETURN "claim:cryptorecoverytrust dot com" in block 967,948
these white hatted funds represent 2.8% of the coldcard exploit pic.twitter.com/c5eYeQMxHQ
— Alex Thorn (@intangiblecoins) September 21, 2026
The two percentages describe different slices of the same incident. The defenders captured a substantial portion of the second wave, but only a small fraction of all Bitcoin tied to the published vulnerability data.
Thorn also said 3.0134 BTC in the transfer came from addresses outside Galaxy’s existing tracked set. Galaxy could not confirm whether those coins were exposed by the same flaw.
That uncertainty is important. Blockchain analysis can follow transactions exactly, but it cannot always establish why an address moved or who controlled it.
Hardware wallets are designed to keep private keys away from internet-connected devices. That protection depends on the wallet creating strong, unpredictable secret material in the first place.
An entropy weakness attacks that foundation. If the randomness used to build a wallet is predictable enough, an attacker may be able to reconstruct the same keys without stealing the physical device.
That is why this episode is more serious than a phishing link or a compromised password. The owners may have followed normal cold-storage practices and still ended up with vulnerable addresses.
The rescue does not make the underlying problem disappear, and it does not prove that every affected user has been identified. It does show that defenders can sometimes turn public blockchain visibility into an advantage: once risky addresses are mapped, rescue transactions can move faster than the thieves.
Moving the Bitcoin was the urgent step. Returning it safely may take longer.
Claimants have to prove they controlled an affected wallet without exposing fresh secrets or creating an opening for impostors. The trust has to evaluate those claims, preserve records and avoid sending recovered funds into another compromised setup.
Owners who believe they are affected should use verified incident and recovery channels, not links sent by strangers. A high-profile recovery effort is exactly the kind of event scammers will imitate.
For the 52.37 BTC now under trust control, the white hats appear to have won the first race. The next test is whether the recovery process can reunite that Bitcoin with its owners without giving attackers a second chance.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
