Self-described white hat hackers have returned 52.37 Bitcoin to a designated recovery fund established for victims of the Coldcard hardware wallet breach, according to Alex Thorn, head of research at Galaxy Research. Thorn reported that the transaction represents the first large-scale donation of Bitcoin made to the recovery fund following the attacks.
The returned sum equals approximately 2.8 percent of the total cryptocurrency assets stolen across all attack vectors targeting Coldcard wallet holders. According to data provided by Thorn, the recovered coins were taken during the second wave of attacks and account for roughly 40 percent of the funds stolen during that specific phase of the breach.

Thorn indicated that cybersecurity specialists from the Security Alliance collective likely rescued the Bitcoins. The security group identified vulnerable wallet addresses containing funds in time and transferred the cryptocurrency before malicious actors could drain them. An additional 45.9 Bitcoin from the second wave remain in unidentified wallets, though Thorn expressed hope that the entire second attack wave was conducted by ethical hackers who will return the remaining funds.

Scale of the Coldcard Exploits
Data compiled by Galaxy Research estimates that 1,789.28 Bitcoin was stolen from 8,865 individual cryptocurrency wallets across three distinct attack waves, representing a total value of approximately 114.7 million dollars at the time of the thefts. The primary breach wave resulted in the theft of 1,082.57 Bitcoin, which currently remains unmoved in wallet addresses controlled by the perpetrators.

The third wave of thefts displayed a different operational structure, with attackers distributing stolen assets across hundreds of separate addresses rather than aggregating them into a single account. Approximately 55 percent of the funds stolen in the third wave, amounting to 116.98 Bitcoin, remain untouched in attacker wallets. However, perpetrators successfully routed 97.09 Bitcoin through cryptocurrency mixers and converted the assets across external blockchain networks.

Firmware Vulnerabilities and Hardware Security
Coldcard hardware wallets, manufactured by Coinkite, are specialized offline security devices designed to store Bitcoin private keys away from internet-connected systems. The exploit series began on July 30 after attackers capitalized on a legacy firmware vulnerability affecting devices updated since March 2021. The affected firmware versions generated cryptographic seed phrases with predictable entropy, allowing attackers to calculate private keys offline without remotely breaching the physical wallet hardware.

Seed phrases, also known as mnemonic recovery phrases, are ordered sequences of words generated by cryptocurrency wallets to derive cryptographic keys. Predictable entropy occurs when a random number generator fails to produce sufficient randomness, making generated keys susceptible to brute-force offline calculation by security researchers or malicious actors.
Crypto Security and Tracking
Galaxy Research is the research division of digital asset management firm Galaxy, while the Security Alliance functions as a non-profit collective of Web3 cybersecurity professionals organized to respond to active exploits. Ethical security researchers frequently monitor vulnerable blockchain addresses to rescue funds before malicious actors can finalize thefts, holding recovered assets in temporary custody or dedicated recovery funds.
Cryptocurrency mixers are specialized privacy protocols that obscure transaction histories by pooling and shuffling funds from multiple users. By passing 97.09 Bitcoin through mixers and bridging them to other blockchains, the third-wave attackers rendered those assets significantly harder for law enforcement and blockchain analytics firms to trace.
Recovery efforts remain active as security researchers monitor public blockchain ledgers for movement from the remaining compromised addresses. While the return of 52.37 Bitcoin marks progress for second-wave victims, investigators continue tracking the 1,082.57 Bitcoin from the initial exploit wave and the remaining unreturned funds across all three attack phases.
