According to Thorn's analysis, the 52.37 BTC represents approximately 2.8% of the total Bitcoin tracked in connection with the exploit.
Whitehats Move 52.37 BTC Into Recovery Trust
Not all Bitcoin moved from vulnerable Coldcard wallets appears to have been taken by malicious attackers.
Whitehat researchers also identified vulnerable wallets and moved some funds before attackers could reach them.
Rather than keeping the Bitcoin, these researchers swept the exposed funds into addresses intended to preserve them until ownership could be verified.
The latest transfer consolidated 52.37 BTC associated with Wave 2 of the incident and several additional tracked footprints.
An OP_RETURN attached to the transaction contained a message directing affected users toward the Crypto Recovery Trust.
OP_RETURN is a Bitcoin transaction feature that allows a small amount of arbitrary data to be permanently recorded on the blockchain without creating a spendable output.
In this case, it provides an onchain reference to the recovery process.
Around 40% of Wave 2 Linked to Whitehat Activity
Thorn said approximately 40% of the Bitcoin associated with Wave 2 has now been identified as whitehat activity.
The newly consolidated 52.37 BTC represents about 2.8% of the total tracked exploit funds.
Another 3.0134 BTC without a previous tracking history also entered the Crypto Recovery Trust address as part of the same transaction.
Thorn said those coins are presumed to represent additional whitehat-recovered Coldcard funds, although that attribution has not yet been confirmed.
That distinction is important because blockchain analysis can establish where Bitcoin moved, but identifying the people or intentions behind an address may require additional evidence.
What Caused the Coldcard Incident?
The Coldcard incident began unfolding publicly on July 30, 2026, when large amounts of Bitcoin started moving from wallets associated with affected Coldcard devices.
The underlying problem was a firmware bug affecting seed generation.
Coldcard devices were designed to generate wallet seeds using hardware-based cryptographically secure randomness.
However, a software integration error caused affected firmware to use a weaker software-based pseudorandom number generator instead of the intended hardware random-number generator.
That significantly reduced the randomness protecting certain wallet seeds.
Attackers could then search through possible seeds offline, derive corresponding Bitcoin addresses and identify vulnerable wallets using publicly available blockchain data.
Once the correct seed was reconstructed, the attacker could derive the wallet's private keys and move its Bitcoin.
Coldcard Devices Were Not Remotely Taken Over
Coinkite has emphasized an important distinction about the incident.
The Coldcard hardware devices themselves were not remotely accessed or taken over.
Instead, the weakness occurred when affected firmware generated wallet seeds.
Once a weak seed had already been created, an attacker did not need physical access to the Coldcard device. The reduced seed entropy made it possible to attempt reconstruction of the corresponding private keys offline.
Coinkite released emergency firmware fixes on July 31 and later published additional security updates following a broader review.
However, updating firmware does not make an existing vulnerable seed secure.
Existing Vulnerable Seeds Still Need Migration
This remains one of the most important points for Coldcard users.
Installing updated firmware prevents the same seed-generation problem when creating new seeds, but it cannot retroactively strengthen a seed that was generated using affected firmware.
Coinkite recommends that potentially affected users generate a new seed using fixed firmware and migrate their Bitcoin away from addresses controlled by the older seed.
The company released firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q following additional security review.
Coldcard's official guidance says users whose seeds may have been generated on affected firmware between 2021 and July 2026 should follow its migration guidance.
What Is the Crypto Recovery Trust?
The Crypto Recovery Trust describes itself as an organization created to support the lawful and transparent recovery of digital assets and return them to their rightful owners.
Its website identifies the entity as the Recovered Digital Asset Statutory Trust of Wyoming, doing business as Crypto Recovery Trust.
Recovered assets are intended to be held while claims and ownership information are reviewed.
Users who believe their Bitcoin may have been recovered can use the trust's website to check the status of a claim and submit supporting information.
Users should independently verify they are accessing the legitimate website before submitting sensitive information, particularly because recovery situations can attract phishing attempts.
Why the Recovery Matters for Bitcoin Users
The Coldcard incident demonstrates that hardware-wallet security depends on more than keeping private keys offline.
Secure seed generation is equally important.
A hardware wallet can remain physically secure while still exposing funds if the randomness used to create its seed is predictable enough for an attacker to reconstruct.
The whitehat recovery also demonstrates another characteristic of Bitcoin's transparent ledger.
Researchers can track movements between addresses, identify patterns associated with an exploit and monitor recovered funds onchain.
However, blockchain transparency alone does not establish legal ownership. Returning recovered Bitcoin still requires a process for determining which claimant legitimately controlled the affected wallet.
What Coldcard Users Should Watch
Users who generated Coldcard seeds using potentially affected firmware should follow Coinkite's current official security and migration guidance.
A firmware update alone does not repair an already weakened seed.
Users who believe Bitcoin was moved from one of their addresses by whitehat researchers can also check the Crypto Recovery Trust's official recovery process.
The attribution of some funds is still developing, including the additional 3.0134 BTC that entered the recovery address without a previous tracking history.
Further blockchain analysis may provide more clarity as investigators continue mapping the exploit and recovery transactions.
Bottom Line
Whitehat researchers have moved 52.37 BTC connected to the Coldcard exploit into an address associated with the Crypto Recovery Trust.
The transaction, confirmed in Bitcoin block 967,948, included an OP_RETURN message directing affected users toward the recovery process.
According to Galaxy Digital's Alex Thorn, the Bitcoin represents approximately 2.8% of the total tracked exploit funds, while roughly 40% of Wave 2 has now been attributed to whitehat activity.
The recovery does not erase the broader security issue. Coldcard's firmware flaw weakened seed generation on affected devices, allowing attackers to reconstruct private keys offline.
For users potentially affected by the vulnerability, the key distinction remains clear: installing fixed firmware protects future seed generation, but an existing vulnerable seed must be replaced and funds migrated to a newly generated secure wallet.