Prefer Koin Bülteni on Google Add as source

Not All Bitcoin Moved in Wallet Attack Was Stolen: New Step for Victims!

Some of the Bitcoin removed from wallets in the Coldcard attack was reportedly moved not by thieves, but by ethical security experts seeking to protect the funds. In this context, 52,37 BTC was collected at a recovery address.

According to a report by CoinDesk citing Alex Thorn, Head of Research at Galaxy Digital, whitehat operators, described as ethical cybersecurity experts, transferred the Bitcoin in question to an address linked to the newly established Crypto Recovery Trust. The goal is to protect the assets until they can be returned to their owners. The transfer itself does not mean that victims have been paid.

52 Bitcoin collected at recovery address

The 52,37 BTC in the funds monitored by Thorn, brought together from transaction traces labeled AA, AU, and AX during the second wave of the attack, accounts for 2,8% of the total tracked attack funds. The transfer was confirmed in block 967.948 of the Bitcoin network.

Thorn also stated that approximately 40% of the funds in the second wave were linked to whitehat activity. This figure reflects the classification made only for the second wave, not the share recovered across the attack as a whole.

In the same transaction, an additional 3,0134 BTC with no previous tracking record reached the recovery address. Thorn said these could also be additional funds protected from the Coldcard attack, but emphasized that the connection had not been verified.

Victims will be able to check their addresses

The OP_RETURN note recorded on the blockchain included a message directing users to the Crypto Recovery Trust domain. According to CoinDesk, victims can search their publicly available Bitcoin addresses on cryptorecoverytrust.com to check whether their funds are among the recovered assets.

This check is intended to provide information about the tracking status of the funds; the report does not specify a completed refund or a definitive payment schedule. Recovery words and private keys should not be shared with any site.

Software update does not eliminate the risk to older wallets

According to CoinDesk, the Coldcard attack began on July 30, and the estimated Bitcoin losses across the three waves that followed exceeded $100 million. In the attack, the wallets were made to generate the data underlying their recovery keys using a weaker software-based source instead of a cryptographically secure random number generator. This enabled attackers to recalculate the keys of some wallets.

Manufacturer Coinkite fixed the vulnerability in the device firmware. However, funds tied to recovery information created using the old method and exposed in the attack reportedly remain at risk. The new recovery transfer is a development related to the earlier attack; it is not being presented as a new wave of attacks.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!