
A total of 52.37 Bitcoin rescued from wallets exposed by a Coldcard flaw was moved to the Crypto Recovery Trust.
White hats transferred 52.37 Bitcoin rescued from wallets exposed by a Coldcard vulnerability to the Wyoming-based Crypto Recovery Trust to return funds to victims.
AI-generated summary
A Coldcard vulnerability exposed certain wallet addresses to security risks.
White hats have transferred Bitcoin they rescued from wallets exposed by a Coldcard vulnerability to a trust set up to return the funds to victims.
A total of 52.37 Bitcoin was moved to an address controlled by Wyoming-based Crypto Recovery Trust, Galaxy Digital head of research Alex Thorn said in an X post on Monday. About 40% of the Bitcoin associated with the second wave was swept by white hats to protect victims’ funds.
Thorn said 3.0134 BTC included in the transfer came from addresses Galaxy had not previously tracked. He said the funds were presumably also rescued from wallets affected by the Coldcard flaw, but that Galaxy could not confirm their origin.
Security researcher and SEAL 911 incident responder Nick Bax said on Sept. 9 that he helped rescue about 50 Bitcoin at the end of July because the funds were “imminently going to be stolen” due to the Coldcard entropy flaw.
Thorn cited a published total of 1,830 BTC across 9,162 addresses linked to the Coldcard vulnerability.
Potential victims can enter their wallet addresses on the Crypto Recovery Trust website to determine whether the trust controls their funds.
Thorn did not immediately respond to Cointelegraph’s request for comment.

European Union financial regulators warn that future quantum computing advancements could compromise blockchain cryptography. While no current computer can execute such attacks, major networks like Bitcoin and Ethereum are already considering mitigation strategies.

A North Korean hacking group known as WaterPlum or Contagious Interview has compromised over 7,000 crypto wallets and 30,000 devices globally. Operating between Dec 2025 and July 2026, the group used fake job interviews to deploy malware and fund Pyongyang.

Microsoft and Coinbase dismantled EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 inboxes across 10,000 organizations. UK police arrested two suspects following investigations into the $1.1 million operation.

Zcash users holding ZEC in the legacy Sprout shielded pool must move their funds before the planned NU7 upgrade or risk losing spending access, according to a community proposal.

A malicious iOS app named FomoPeek, distributed through Apple's App Store, was found to contain kernel exploits that stole nearly $580,000 in cryptocurrency by accessing wallet data and Keychain information, according to a SlowMist investigation with OKX security team.

XRP Ledger validators have conditionally activated the BatchV1_1 amendment for Sept. 29 at 14:06:41 UTC, converting a previously identified security flaw into a live test of the network's amendment process. The fix addresses a critical authorization vulnerability that could have allowed unauthorized transactions if activated on mainnet. Activation depends on maintaining over 80% validator support for two weeks, with current support at 30 of 35 trusted validators. The update enables atomic transaction flows while requiring client software upgrades to avoid consensus disruption.