Ethical Hackers Secure 52 Bitcoin Following Coldcard Wallet Exploit
Ethical Hackers Secure 52 Bitcoin After Coldcard Breach
Ethical hackers, often called "whitehats," have moved 52.37 Bitcoin (BTC) to a recovery trust following a security breach in July. The move was made to protect the assets from malicious actors after an exploit affected Coldcard hardware wallets, which are physical devices used to store digital currency offline.
Important Details About the Recovery
- 52.37 BTC was moved to a specific recovery trust address.
- The July exploit caused estimated losses of more than $100 million.
- Approximately 40% of the second wave of stolen funds has been identified as whitehat activity.
- Coinkite has patched the Coldcard firmware, but older wallets remain at risk.
Information From Galaxy Digital
Alex Thorn, Head of Research at Galaxy Digital, reported that these ethical cybersecurity professionals swept the funds to keep them safe until they could be returned to their owners. The transaction was confirmed in block 967,948 and included a message pointing users to "cryptorecoverytrust dot com." This recovered amount represents about 2.8% of the total funds tracked from the exploit.
The Coldcard Wallet Vulnerability
The exploit began on July 30 and targeted a weakness in how the wallets generated "seeds." A seed is a master password used to access a crypto wallet. The affected wallets used a weak software-based method to create these seeds instead of the device's dedicated random number generator. This allowed hackers to reconstruct the passwords and gain access to the funds. While Coinkite, the manufacturer, has issued a fix, any wallet created with the old software remains vulnerable.
What Is Confirmed
It is confirmed that 52.37 BTC was consolidated and moved to the recovery address. It is also confirmed that the security issue was caused by weak software-based randomness and that a firmware patch is now available for Coldcard users.
What Is Still Unclear
While 52.37 BTC is confirmed as part of the recovery, an additional 3.0134 BTC also entered the trust address. Alex Thorn stated that this is likely more recovered funds, but its origin and status as a whitehat recovery remain unconfirmed.
How Victims Can Check Their Funds
Victims of the July Coldcard exploit can visit cryptorecoverytrust.com to see if their Bitcoin has been recovered. By searching for their specific wallet address on the website, users can determine if the ethical hackers have secured their assets for eventual return.