White hat security researchers have transferred 52.37 Bitcoin to an address controlled by the Wyoming-based Crypto Recovery Trust. The funds were rescued from wallets exposed by a vulnerability in Coldcard hardware wallets. Galaxy Digital head of research Alex Thorn confirmed the transfer on Monday via an X post, noting that approximately 40% of the Bitcoin associated with the second wave of attacks was swept by white hats to protect victims’ assets.
Thorn specified that 3.0134 BTC included in the transfer originated from addresses Galaxy had not previously tracked, though these funds were presumably also rescued from wallets affected by the Coldcard flaw. Security researcher Nick Bax previously stated on Sept. 9 that he helped rescue about 50 Bitcoin at the end of July due to an imminent theft risk caused by the Coldcard entropy flaw. Thorn cited a published total of 1,830 BTC across 9,162 addresses linked to the vulnerability. Potential victims can verify if the trust controls their funds by entering wallet addresses on the Crypto Recovery Trust website.
The successful evacuation of 52.37 BTC demonstrates the operational capacity of coordinated white hat efforts to mitigate losses during active exploit windows. By moving funds to a neutral, jurisdictionally defined entity like the Wyoming-based Crypto Recovery Trust, the industry is establishing a precedent for structured asset recovery rather than relying on ad hoc custodial arrangements. This approach reduces the immediate risk of secondary theft while preserving the chain of custody necessary for eventual restitution to legitimate owners.
However, the reliance on voluntary white hat intervention highlights persistent gaps in vendor security protocols and user protection mechanisms within the hardware wallet sector. While the Crypto Recovery Trust provides a centralized point for victim verification, the existence of untracked funds suggests that comprehensive monitoring of all affected addresses remains challenging. Future incidents will likely test whether this model can scale effectively or if regulatory frameworks will need to mandate more robust insurance or escrow solutions for critical infrastructure vulnerabilities.


