
White hats sweep 52.37 BTC tied to Coldcard flaw into Wyoming Crypto Recovery Trust
Galaxy’s Alex Thorn said the move covered about 40% of the exploit’s second wave, while 3.0134 BTC remains unverified in origin.
White hats moved 52.37 BTC linked to the Coldcard entropy flaw to an address controlled by Wyoming-based Crypto Recovery Trust, positioning the funds for victim recovery. Galaxy Digital research head Alex Thorn framed the transfer as roughly 40% of the exploit’s “second wave,” but said a 3.0134 BTC slice came from previously untracked addresses with unconfirmed provenance.
Key Takeaways
- 52.37 BTC tied to the Coldcard entropy-flaw incident was transferred to an address controlled by the Wyoming-based Crypto Recovery Trust, per Galaxy Digital head of research Alex Thorn.
- The sweep was described as about 40% of the Bitcoin associated with the exploit’s “second wave,” implying the defensive operation is still competing with active attacker activity.
- 3.0134 BTC included in the transfer came from addresses Galaxy had not previously tracked, and Galaxy could not confirm where those funds originated.
- A published exposure estimate cited by Thorn put the vulnerability at 1,830 BTC across 9,162 addresses, and affected users can check whether the trust controls their funds via the Crypto Recovery Trust website.
52.37 BTC Lands in a Wyoming Recovery Trust as the Second Wave Plays Out
A cluster of Bitcoin tied to the Coldcard “entropy flaw” incident has been consolidated into a recovery vehicle, with 52.37 BTC moved to an address controlled by the Wyoming-based Crypto Recovery Trust, according to an X post from Galaxy Digital head of research Alex Thorn.
The operational framing matters. Thorn described the transfer as part of the exploit’s ongoing “second wave,” and said white hats swept the coins to protect victims’ funds, which is the typical playbook when defenders believe exposed UTXOs are at risk of being drained before users can rotate keys or move funds themselves.
For traders who track exploit-driven flows, the immediate question is not whether 52.37 BTC is large in absolute terms, but whether the on-chain activity is trending toward containment or escalation. A defensive sweep into a known custody endpoint can reduce near-term sell-pressure risk from attacker-controlled wallets, but it also concentrates coins into a single address that may later distribute funds back out as claims are processed.
The incident itself centers on an “entropy flaw,” a weakness in randomness generation that can make private keys predictable and wallets vulnerable to theft. Coldcard is a hardware wallet product used for Bitcoin self-custody, and the presence of a “second wave” label suggests the exposure is being treated as a sequence of address sets becoming vulnerable or being actively targeted over time.
What the ~40% ‘Second-Wave’ Sweep Suggests About Remaining Exposed UTXOs
Thorn said the 52.37 BTC sweep represented about 40% of the Bitcoin associated with the exploit’s second wave. Read literally, that implies a majority of the second-wave-linked BTC was not captured in this consolidation, either because it was already moved elsewhere, remains dormant in exposed UTXOs, or was taken by an attacker before defenders could front-run it.
That “race” dynamic is the part market participants tend to misprice. When defenders are sweeping UTXOs, they are effectively competing for the same spendable outputs an attacker would target, and the outcome can change the flow profile quickly. Coins that end up in attacker-controlled wallets often become a monitoring problem for exchanges and compliance teams, while coins that end up in a recovery trust become an operational distribution problem that can play out over weeks.
The second-order effect is that labeling becomes messy in real time. A sweep can be protective and still create temporary uncertainty about who controls what, especially when multiple responders are moving funds under time pressure. That uncertainty is why the “second wave” framing is more useful than a single headline number, because it tells traders the incident is still being actively worked rather than cleanly resolved.
Nick Bax, a security researcher and SEAL 911 incident responder, previously described the urgency behind these moves. On Sept. 9, Bax said he helped rescue about 50 BTC at the end of July because the funds were “imminently going to be stolen” due to the Coldcard entropy flaw.
The 3.0134 BTC Attribution Gap and the Bigger Exposure Numbers
The clean narrative of “rescued funds” has a measurable caveat. Thorn said 3.0134 BTC included in the 52.37 BTC transfer came from addresses Galaxy had not previously tracked, and that Galaxy could not confirm the origin of those funds, even though Thorn said they were presumably also rescued from wallets affected by the Coldcard flaw.
That 3.0134 BTC attribution gap is small relative to the full transfer, but it is large enough to matter for anyone trying to maintain a precise ledger of stolen versus rescued coins. In practice, it means the destination address can be confidently described as controlled by the Crypto Recovery Trust, but not every satoshi in the inbound transfer can be cleanly tagged to the known exposure set based on Galaxy’s tracking at the time of the post.
The other number in Thorn’s thread is the one that keeps this from being a tidy “funds recovered” story. Thorn cited a published total exposure estimate of 1,830 BTC across 9,162 addresses linked to the Coldcard vulnerability. Even if only a fraction of that exposure is actively exploited, it leaves room for more on-chain movement to surface, and for additional “waves” of activity to be identified after the fact.
For affected users, the recovery path is centralized around the trust’s custody and verification flow. Potential victims are directed to enter their wallet addresses on the Crypto Recovery Trust website to determine whether the trust controls their funds.
Signals Traders Can Monitor: Further Sweeps, Attacker Moves, and Victim-Claim Activity
The most actionable signals from here are on-chain and procedural rather than narrative.
First, additional transfers into or out of the Crypto Recovery Trust-controlled address would indicate whether white hats are still consolidating exposed UTXOs or beginning to distribute funds back to claimants. Either direction changes the flow profile, and repeated inbound sweeps would reinforce that the defensive operation is ongoing.
Second, any follow-up identification from Galaxy regarding the 3.0134 BTC sourced from previously untracked addresses would tighten attribution. If those inputs are later linked to the published exposure set, it strengthens the “rescued” label. If they remain unverified, the accounting stays noisy.
Third, movements from addresses tied to the broader exposure estimate of 1,830 BTC across 9,162 addresses are the clearest tell for whether the incident is contained. Fresh spends from that set can signal attacker sweeps, defensive front-running, or late user self-rescues, and the market impact depends on which bucket dominates.
Finally, updates from incident responders such as Bax or from Galaxy on whether the second wave is contained would help resolve the biggest open question the packet leaves unanswered: how much BTC is confirmed stolen versus rescued across waves.
My Read: This Is a Flow Story Until the Accounting Gets Clearer
The transfer is being read as a recovery milestone, and the more accurate framing is that it is evidence of an active defensive operation. Thorn’s own language anchors it to a “second wave,” and the ~40% figure is the tell that this is still a live contest over exposed UTXOs rather than a closed incident with a final tally.
The threshold that matters is whether the next round of on-chain moves reduces uncertainty instead of adding to it, because the 3.0134 BTC attribution gap is a reminder that even “rescues” can carry provenance risk in the moment. If Galaxy can tighten labeling while additional sweeps consolidate into the trust without fresh attacker-linked dispersals, the setup starts to look like containment with an orderly claims process rather than a rolling exploit that keeps leaking into the market.