About 40% of Coldcard Wave 2 Outflows Were Whitehat Rescues, Galaxy Says
Key Takeaways
- •Galaxy Digital's blockchain monitoring indicates that roughly 40% of the Coldcard exploit's second attack wave was whitehat activity rather than criminal theft.
- •A transaction confirmed in block 967,948 moved 52.37 BTC, about 2.8% of tracked exploit funds, from Wave 2 and three attacker clusters labeled Footprint AA, AU and AX to a recovery-trust address carrying the OP_RETURN message 'claim:cryptorecoverytrust dot com.'
- •The same recovery effort included a related September 21 transfer of 40.71 BTC, worth about $3.31 million, involving 11 addresses, 20 inputs and 480 outputs.
- •The Coldcard exploit began on July 30 and drained an estimated $100 million to $130 million, with an earlier count of roughly 1,816 BTC taken from more than 5,200 addresses.
- •The vulnerability traces to a March 2021 firmware change that made some Coldcard seeds rely on a software random-number source, and although Coinkite patched the firmware, coins under old seeds remain at risk until moved to newly generated ones.

Alex Thorn, head of research at Galaxy Digital, says the second wave of attacks in the Coldcard wallet exploit was about 40% whitehat activity, based on the firm's blockchain monitoring. The figure is a useful corrective to headline loss totals, since coins leaving compromised wallets are not all in criminal hands. In a post on X, Thorn tracked 52.37 BTC being dispatched to an address tagged for a new recovery trust.
52.37 BTC landed in a fresh address in block 967,948
According to Thorn, the 52.37 BTC came from coins taken in Wave 2 and three attacker clusters that Galaxy labeled Footprint AA, AU and AX. Clustering addresses by shared behavior is a standard on-chain tracing technique, letting researchers attribute fund flows to a single actor even as they spread across many addresses. The funds reached a new address confirmed in block 967,948.
The transaction carried an OP_RETURN note — a short message embedded in a Bitcoin transaction — which read "claim:cryptorecoverytrust dot com." Thorn pegged the haul at 2.8% of tracked exploit funds. The same transaction also sent another 3.0134 BTC with no prior tracking history to the same recovery address. Thorn said it was probably more whitehat-recovered Coldcard money, though he marked that link as unconfirmed.
As part of its blockchain monitoring, Galaxy Research also detected a related transfer of 40.71 BTC, worth about $3.31 million, on September 21. That transaction involved 11 addresses, 20 inputs and 480 outputs, and carried the same recovery-trust message.
Losses peaked near $130 million from a March 2021 firmware flaw
Whitehats are security researchers who use attackers' techniques to snatch exposed coins before criminals do. Some of the outflows from victim wallets were therefore rescues, with coins parked until owners come forward. Victims can search wallet addresses at cryptorecoverytrust.com to check whether their funds were pulled to safety. Most stolen bitcoin remains dormant in attacker wallets. The open question is how many owners step forward to claim parked coins — the step that turns rescues into actual recoveries and firms up the true loss tally.
The Coldcard exploit began July 30 and unfolded in multiple batches over the following days. Damage estimates range from more than $100 million to a high of about $130 million. Cryptopolitan's earlier report counted approximately 1,816 BTC drained from over 5,200 addresses, worth between $114 million and $116 million at the time.
The flaw traces back to a firmware change in March 2021. Some seeds generated by Coldcard firmware used a software random-number source instead of the device's hardware generator, and attackers rebuilt those seeds offline to drain wallets. Coinkite, the maker of the Coldcard hardware wallet, has since patched its firmware, but the exposure follows the seed rather than the device: coins already exposed under old seeds remain at risk until their owners move them to freshly generated ones, which is what keeps whitehat rescues and the recovery trust's claim process relevant even with patched firmware in circulation.