Whitehat operators have transferred 52.37 BTC to an address associated with a newly established recovery trust, according to Alex Thorn, head of research at Galaxy Digital.
The address includes an OP_RETURN message directing users to “claim:cryptorecoverytrust dot com.” The transfer is part of efforts to recover funds following the Coldcard hardware wallet exploit that began in late July.
The attack started on July 30, with several waves of exploits, identified as Waves 1, 2 and 3, occurring over the following days. The attacks are estimated to have resulted in more than $100 million in Bitcoin losses.
The vulnerability involved Coldcard wallets generating seed phrases with a weaker software-based source of randomness instead of the device’s dedicated random-number generator. This flaw potentially allowed attackers to reconstruct affected wallet seeds and gain access to funds.
Coinkite, the company behind Coldcard, has since released a firmware patch addressing the vulnerability. However, the update does not eliminate the risk for funds associated with seed phrases that were already compromised.
Thorn said some of the Bitcoin transferred from affected wallets was not taken by criminals. Instead, whitehat hackers — cybersecurity researchers who use similar techniques to identify and address vulnerabilities — moved certain funds to protect them from malicious actors.
The recovered assets were swept into secure custody with the intention of eventually returning them to their rightful owners.
The latest 52.37 BTC transfer consisted of funds consolidated from Wave 2 of the tracked exploit addresses, along with three additional traces identified as AA, AU and AX. The coins were sent to an address containing the OP_RETURN recovery message, with the transaction confirmed in Bitcoin block 967,948.
According to Thorn, the 52.37 BTC represents about 2.8% of the total exploit funds being tracked. Approximately 40% of Wave 2 has now been attributed to whitehat activity.
Another 3.0134 BTC with no previous tracking history was included in the same transaction and sent to the recovery trust address. Thorn said the coins are believed to be additional Bitcoin recovered by whitehat operators, although that connection has not yet been confirmed.
Coldcard victims can determine whether their funds were among those recovered by visiting cryptorecoverytrust.com and checking their wallet addresses.

More Stories
Bitcoin, Ether Perpetual Trading on Kalshi Shows Unusual Repetitive Activity
Bitcoin Rebounds From Asian Lows as Falling Oil Boosts Risk Appetite
Bitcoin Trades Near $86K as U.S. Stocks Edge Higher