White Hats Beat Coldcard Attackers, Rescuing Millions of Dollars in Bitcoin – Bitcoin News

White Hats Beat Coldcard Attackers, Rescuing Millions of Dollars in Bitcoin – Bitcoin News

Key Takeaways

The Coldcard exploit looked like a straightforward disaster when bitcoin began disappearing from vulnerable wallets this summer. Attackers had discovered that some Coldcard seeds could be reconstructed offline, and the race was suddenly on to reach exposed coins. But Thorn’s investigation has uncovered a fascinating wrinkle in that story.

Some of the people sweeping those wallets weren’t thieves at all. They were white hat hackers trying to beat the thieves to the money, and at least 52.37 BTC appears to have survived that race.

Thorn Spots 52.37 BTC Heading to a Trust

“COLDCARD WHITE HAT MOVES FUNDS TO TRUST,” Thorn wrote Tuesday, before laying out what he had spotted onchain. According to the Galaxy researcher, “52.37 BTC comprised of coins from Wave 2, Footprints AA, AU, AX” were consolidated into a new address in block 967,948.

The transaction even carried an OP_RETURN message reading “claim:cryptorecoverytrust dot com,” effectively leaving an onchain signpost explaining where the rescued bitcoin had gone. Thorn calculates that those rescued coins amount to “2.8% of the Coldcard exploit.” More importantly, his analysis changes the picture surrounding Wave 2, one of several groups of transactions researchers have been tracking since the drains began.

“We now know that ~40% of Wave 2 was actually white hats sweeping coins to protect victim funds,” Thorn explained. Those coins, he added, “have now apparently been delivered to an address controlled by Crypto Recovery Trust,” a Wyoming trust established to help legitimate white hats get recovered assets back to victims.

The Numbers Get Stranger

The 52.37 BTC—more than $4.4 million worth, as of this writing—may not be the whole haul. Thorn noticed another 3.0134 BTC entering the Crypto Recovery Trust address in the same transaction, but he is deliberately cautious about counting it.

“We have not seen these coins before,” he wrote in his X thread, adding that they are “presumably” additional Coldcard funds recovered by white hats, although his team cannot yet confirm their origin.

That caution matters because Thorn is trying to reconstruct an exploit involving a great deal more money. His accounting of Waves 1, 2, and 3, together with the trust funds, covers 1,393 BTC, or 76.1% of the published Coldcard exploited total. Wave 1 alone remains untouched at 1,082.57 BTC. Wave 3 has 116.98 BTC untouched, while 97.09 BTC was coinjoined or routed through Thorchain to Ethereum, and then attackers used Tornado Cash to mix the ether. Footprints AX, AA and AU, by contrast, are now considered “100% white-hatted.”

What About the Rest of the Bitcoin?

The mystery isn’t completely solved. Thorn said researchers still don’t know whether the remaining 60% of Wave 2 funds were taken by malicious attackers or by another group of white hats. What he can say is that the two portions appear to involve different operators. Thorn has also spoken with individual Coldcard victims represented in both parts of Wave 2, strengthening the link between those transactions and the broader Coldcard incident.

“We do not know if the other 60% of funds taken in Wave 2 are also white hats,” Thorn wrote. He said that, white hat or not, the remaining coins appear to have been handled by “a different operator (or operators)” from the group whose bitcoin ultimately reached Crypto Recovery Trust. In other words, investigators can now explain a large chunk of what initially looked like stolen bitcoin, but another substantial pile remains anyone’s guess.

Proving Who Really Owned the Bitcoin

Recovering the coins creates another problem: How does a trust determine who actually owned them when both the victim and attacker may possess credentials capable of accessing the wallet? When an X user put that question to Thorn, he said there are several pieces of evidence that could be combined rather than relying on one definitive test.

“Could do it a few ways,” Thorn replied, suggesting that “several creates a preponderance.” Among the evidence he listed were device forensics showing who created the seed first, exchange know-your-customer records showing withdrawals to an address that was subsequently drained, victims previously providing him with an xpub or zpub extended public key, and an early FBI report.

Crypto Recovery Trust also allows Coldcard victims to search their addresses to determine whether their bitcoin may be among the funds rescued by white hats.

The Coldcard Bug That Started the Race

Behind Thorn’s detective work is a Coldcard firmware bug that weakened wallet seed generation, allowing attackers to reconstruct seeds remotely. Beginning July 30, the exploit ultimately affected more than 8,600 addresses and roughly 1,779 BTC.

Thorn’s latest finding adds a twist. Basically, white hats discovered vulnerable coins too, beating attackers to 52.37 BTC and moving it into protective custody. Now the challenge is proving ownership and returning the bitcoin to rightful owners.