Whitehat operators moved 52.37 BTC linked to the July Coldcard exploit into an address tied to Crypto Recovery Trust.
Galaxy Digital researcher Alex Thorn identified the Bitcoin through blockchain transactions linked to the exploit.
Thorn linked the funds to the Wave 2 cluster and wallet footprints labelled AA, AU, and AX.
The Bitcoin network recorded the consolidation in block 967,948 during the transfer.
Thorn said the 52.37 BTC equals 2.8% of the Coldcard exploit funds that Galaxy tracks.
The transaction included an OP_RETURN message that directed users to Crypto Recovery Trust’s claims website.
Crypto Recovery Trust operates as a Wyoming statutory trust for recovered digital assets.
Agentic Trace LLC serves as the trustee, according to information published by the Trust.
The Trust holds recovered Bitcoin while it verifies claims from people who say they owned affected wallets.
People seeking recovered Bitcoin can submit ownership evidence through the trust’s claims process.
Crypto Recovery Trust reviews blockchain records and ownership evidence when assessing claims for recovered Bitcoin.
The trust also checks claimants and recovered assets for sanctions restrictions before making distributions.

Recovery Trust Handles Claims for Rescued Bitcoin
The 52.37 BTC transfer follows earlier whitehat efforts to rescue Bitcoin from vulnerable Coldcard wallets.
Digital Asset Recovery Trust previously reported securing more than 50 BTC from affected addresses.
DART said whitehat researchers moved more than 50 BTC before attackers could steal the funds.
The Digital Asset Recovery Trust placed the recovered Bitcoin in a trust, so researchers did not hold the assets in their own wallets.
The Trust can require additional legal review when multiple people claim ownership of the same recovered Bitcoin.
Such reviews can also apply when law enforcement or sanctions issues affect recovered assets.
The claims process therefore requires evidence before the trust distributes rescued Bitcoin.
The wider Coldcard incident involved more Bitcoin than the latest recovery transfer.
The first attack wave reportedly drained about 594 BTC from roughly 500 wallets within about 25 minutes.
Meanwhile, later research identified four attack waves and estimated that about 1,816 BTC moved from more than 5,200 addresses.
The figures vary because researchers have expanded the identified wallet clusters over time.
Coinkite has not published one definitive figure covering every Bitcoin loss linked to the incident.
Thorn’s 2.8% figure therefore applies specifically to Galaxy’s tracked exploit funds.

Coldcard Firmware Fixes Do Not Repair Vulnerable Seeds
The Coldcard exploit began with a seed-generation flaw in firmware that affected certain devices.
Coinkite said the affected process used Yasmarang instead of the intended hardware random generator.
The flawed process generated some wallet seeds with weaker randomness than Coldcard intended.
Attackers could recreate private keys from vulnerable seeds and access Bitcoin held by affected wallets.
Coinkite released firmware updates after identifying the seed-generation flaw in affected Coldcard devices.
However, a firmware update cannot change a vulnerable seed that the device generated before the fix.
The current recommended firmware for Mk4 and Mk5 devices is version 5.6.2.
The recommended release for Q devices is version 1.5.2Q. Users with vulnerable Coldcard seeds must create new seeds after installing the corrected firmware.
Users must then move their Bitcoin from addresses linked to vulnerable seeds into wallets with new seeds.
Coinkite also recognises an exception for users who added enough independent dice-generated entropy.

