Tag: Alex Thorn

  • Whitehats Transfer 52 Bitcoin from Coldcard Hack to Recovery Trust

    Whitehats Transfer 52 Bitcoin from Coldcard Hack to Recovery Trust

    Key Highlights

    • Ethical hackers transferred 52.37 BTC to a newly formed recovery trust address as part of remediation efforts from the July Coldcard hardware wallet exploit.
    • The multi-wave attack, beginning July 30, exploited a firmware vulnerability that forced wallets to use a weaker software-based random number generator, exposing over $100 million in bitcoin.
    • Coinkite has patched the firmware, but funds derived from compromised seeds remain at risk regardless of the update.

    Whitehat Operators Secure 52.37 BTC in Coldcard Recovery Effort

    “Whitehat operators” have moved 52.37 BTC to an address linked to a newly formed recovery trust, according to Galaxy Digital’s Head of Research Alex Thorn. The transfer represents a significant development in the ongoing fallout from July’s Coldcard hardware wallet exploit, which began on July 30 and unfolded across multiple attack waves—designated as waves 1, 2, and 3—in subsequent days. Estimated losses from the incident have surpassed $100 million in bitcoin.

    Firmware Vulnerability Enabled Seed Reconstruction

    The attack exploited a critical weakness in the Coldcard’s firmware implementation. Attackers manipulated affected devices into generating wallet seeds using a weaker software-based random number source instead of the wallet’s dedicated hardware random number generator. This deviation made a subset of seeds vulnerable to reconstruction by malicious actors, effectively compromising the cryptographic foundation of the affected wallets. Coinkite, the manufacturer of Coldcard, has since released a firmware patch to address the vulnerability.

    Patched Firmware Does Not Secure Previously Exposed Funds

    Despite the availability of a firmware update, Coinkite has clarified that funds already exposed under the old, compromised seeds remain at risk regardless of the patch. The cryptographic weakness pertains to the seed generation process itself; once a seed has been generated using the flawed entropy source, updating the device firmware cannot retroactively secure the private keys derived from that seed. This distinction leaves a significant volume of bitcoin vulnerable to potential theft unless proactive measures are taken.

    Ethical Hackers Intervene to Protect At-Risk Assets

    According to Thorn, not all funds moved from victim wallets were taken by malicious actors. A portion was swept by “good guys”—ethical cybersecurity professionals who use hacking skills to identify and remediate security weaknesses. These whitehat operators intervened specifically to remove the at-risk bitcoin from vulnerable addresses and place them into secure custody within the recovery trust, preserving the assets until they can be safely returned to their rightful owners.

    Why This Matters

    The Coldcard exploit underscores a persistent risk in the hardware wallet sector: implementation flaws in entropy generation can undermine the air-gapped security model that cold storage devices promise. While Coinkite’s patch prevents future seed generations from being compromised, the incident highlights the irreversible nature of seed exposure—once a mnemonic phrase is generated with insufficient entropy, the resulting private keys are permanently weakened. The formation of a recovery trust and the active participation of whitehat operators represent an emerging cooperative defense model in the bitcoin ecosystem, where ethical researchers race against malicious actors to secure funds derived from known cryptographic weaknesses. The situation remains fluid, with the total scope of affected addresses and the ultimate recoverability of swept funds still unfolding.

    Frequently Asked Questions

    How many bitcoin were moved to the recovery trust by whitehat operators?
    52.37 BTC were transferred to an address linked to a newly formed recovery trust as part of the remediation effort.
    Does updating Coldcard firmware protect funds from seeds generated before the patch?
    No. Coinkite has stated that funds exposed under the old, compromised seeds remain at risk regardless of the firmware update, because the vulnerability lies in the seed generation process itself, not in the device’s ongoing operation.
    What caused the Coldcard wallet seeds to be vulnerable?
    The exploit forced affected wallets to generate seeds using a weaker software-based random number source instead of the dedicated hardware random number generator, making those seeds susceptible to reconstruction by attackers.
  • Bitcoin Clears Key Hurdle That Historically Preceded Major Bull Runs

    Bitcoin Clears Key Hurdle That Historically Preceded Major Bull Runs

    Key Highlights

    • Bitcoin closed the week ended September 20 above its 50-week moving average for the first time in 45 weeks, signaling a potential trend reversal.
    • The cryptocurrency gained nearly 6% during the week, trading around $81,000 and extending its rebound to 29% over the past 35 days.
    • Galaxy Research Head Alex Thorn described the weekly close above the key moving average as “a potentially important confirmation that the market’s bear phase may have run its course and a new uptrend is upon us.”

    Bitcoin Breaks 45-Week Barrier Above Critical 50-Week Moving Average

    Bitcoin (BTC) has cleared a major technical hurdle that had resisted bullish attempts for nearly a year. For the first time since late 2023, the world’s largest cryptocurrency posted a weekly close above its 50-week moving average, a development market analysts are interpreting as a potential confirmation that the prolonged bearish phase has concluded.

    The weekly candlestick close—recorded at 23:59 UTC on Sunday, September 20—shows Bitcoin settling around $81,000 after a weekly gain of nearly 6%. This advance extends the asset’s recovery to approximately 29% over the preceding 35-day period. Unlike previous instances where price action briefly pierced the moving average only to retreat, this week’s candle closed decisively above the indicator, a distinction technical analysts consider significant for trend validation.

    Why the Weekly Close Carries More Weight Than Intraday Tests

    Bitcoin trades continuously across global exchanges, but technical analysis frameworks rely on defined session closes—daily at 00:00 UTC and weekly at 23:59 UTC on Sundays—to construct candlestick charts. A weekly close above a major moving average carries substantially more analytical weight than an intraday or intraweek breach that fails to hold into the close.

    The 50-week moving average represents the arithmetic mean of weekly closing prices over roughly the past year. In Bitcoin market analysis, this metric serves as a widely watched proxy for the asset’s long-term trend direction. When price action sustains above this level on a weekly basis, it historically correlates with the early stages of sustained uptrends; conversely, extended periods below the average typically coincide with bearish or consolidation phases.

    Analyst Perspective: Galaxy Research Signals Trend Shift

    Commenting on the technical development, Galaxy Research Head of Research Alex Thorn characterized the weekly close as “a potentially important confirmation that the market’s bear phase may have run its course and a new uptrend is upon us.” Thorn’s assessment underscores the significance market participants attach to the 50-week average as a regime-change indicator rather than merely a short-term support or resistance level.

    Galaxy Digital, the financial services and investment management firm founded by Mike Novogratz, operates Galaxy Research as its dedicated market analysis division. The firm’s commentary often influences institutional sentiment given its focus on digital asset markets and its position as a bridge between traditional finance and the cryptocurrency ecosystem.

    Why This Matters

    The 50-week moving average breach represents more than a standalone technical signal; it occurs against a backdrop of evolving macroeconomic conditions, including anticipated shifts in global monetary policy and growing institutional adoption through spot exchange-traded products in major markets. A sustained weekly close above this threshold could attract trend-following capital allocation strategies that use the 50-week average as a systematic entry filter. However, market structure analysts caution that the true test lies in whether Bitcoin can convert the former resistance into support during subsequent weekly candles, particularly if macroeconomic volatility prompts risk-off sentiment across broader financial markets.

    Frequently Asked Questions

    What is the 50-week moving average and why is it significant for Bitcoin?

    The 50-week moving average calculates the average weekly closing price of Bitcoin over approximately the past year. Technical analysts use it as a long-term trend indicator; sustained trading above it typically signals a bullish regime, while extended periods below suggest bearish or consolidation conditions.

    How does a weekly candle close differ from an intraday price move?

    A weekly candle closes at 23:59 UTC every Sunday, capturing the full week’s price action. Analysts consider a weekly close above a key level more reliable than an intraday breach because it reflects sustained conviction across all global trading sessions rather than a temporary liquidity-driven spike.

    What was Bitcoin’s price performance during the week of this breakout?

    Bitcoin rose nearly 6% during the week ended September 20, closing around $81,000. This weekly gain contributed to a broader 29% rebound over the preceding 35-day period.

  • New Clues Emerge in Satoshi’s Bitcoin Genesis Block Puzzle, but Mystery Remains

    New Clues Emerge in Satoshi’s Bitcoin Genesis Block Puzzle, but Mystery Remains

    A Bitcoin puzzle built from information in the Genesis Block has attracted attention from blockchain analysts and the wider Bitcoin community, but it remains unsolved.

    Bitcoin puzzle uses data from the Genesis Block

    The puzzle was created on August 23, 2026, using information contained in the Genesis Block created by Bitcoin creator Satoshi Nakamoto.

    According to the Galaxy Research X account, the puzzle was hidden in human-readable text in Bitcoin Block 963,629. Its creator used the information to generate a wallet with extremely low entropy, which he said required no backup.

    Galaxy Research said the puzzle creator answered two questions intended to help others solve the challenge. The first asked whether the witness script was a hash lock, a multisig or something else. The creator indicated that it was a multisig.

    The second question asked how many keys were involved, what threshold applied and how the keys were derived from the Genesis Block. The puzzle creator answered that there were two keys, adding: “both required. The rest is for you to derive.”

    In a follow-up post on August 25, Galaxy Research said the puzzle jackpot had reached 125,779 sats and shared additional clues from the creator:

    “The witness script is a multisig. Two keys, both required. The rest is for you to derive. Both keys use the same Genesis field, and there is no hash. Both keys are derived independently from Genesis.”

    Puzzle jackpot reaches 142,779 sats

    Galaxy Head of Research Alex Thorn recently highlighted his efforts to solve the Bitcoin puzzle, saying he had been working on it.

    i’ve been working on this puzzle a bitthe jackpot is currently 142,779 sats (~$111)i haven’t myself sent in any requests for hints, but others have. based on the hints, we assume:- a 2-of-2 multisig- both keys from the same Genesis field with no hash applied- derived… https://t.co/afCkDj1Kxe pic.twitter.com/gFo5tFNZcK
    — Alex Thorn (@intangiblecoins) August 29, 2026

    In the X post, Thorn said the puzzle jackpot stood at 142,779 sats, or nearly $111. He added that he had not personally requested any hints, although other participants had.

    Based on the available clues, Thorn listed the following assumptions:

    “a 2-of-2 multisig, both keys from the same Genesis field with no hash applied, derived independently, along the BIP48 path root > multisig > mainnet > genesis_data > script_type, the field is one The Times newspaper printed.”

    Using these clues, Thorn said he had searched through more than 19.3 billion candidate scripts but eliminated them from consideration.

    Bitcoin’s Genesis Block remains central to the challenge

    The Genesis Block, also known as Block 0, is the first block ever mined on the Bitcoin blockchain. Satoshi Nakamoto mined it on January 3, 2009, and embedded the hidden message, “The Times 03/Jan/2009 Chancellor on brink of second bailout for banks,” a headline published by The Times on the same date.

    The message remains one of Bitcoin’s most recognizable historical artifacts, and its connection to the puzzle is central to the ongoing challenge.

    The Bitcoin puzzle remains unsolved, but Thorn invited others working on it to collaborate in an effort to claim the jackpot.

  • Zcash (ZEC) Price Rise Is a Red Flag for Bitcoin (BTC), Warns CryptoQuant Analyst

    Zcash (ZEC) Price Rise Is a Red Flag for Bitcoin (BTC), Warns CryptoQuant Analyst

    The rapid ascent of the privacy-centric cryptocurrency Zcash (ZEC) is raising alarms among on-chain analysts, who view the sudden rally as a significant warning sign for Bitcoin (BTC). While spot exchange-traded funds (ETFs) recently drew retail capital into the digital asset space, researchers have flagged critical signs of overheating in the cryptocurrency derivatives market.

    Historical market cycles point to a troubling trend: unusual surges in Zcash during periods when the leading cryptocurrency is consolidating have often served as a reliable leading indicator of an impending market-wide correction. According to recent data from CryptoQuant, the Zcash risk metric has climbed into extreme territory, flashing a clear warning signal for Bitcoin investors. This altcoin rally is unfolding while Bitcoin remains bound within a trading range of $60,000 to $80,000, struggling to break out past its previous highs.

    Analyst Warnings and Historical Patterns

    CryptoQuant analyst Maartun highlighted the suddenness of the move, pointing out that the privacy coin “just ripped 70% in a matter of days,” which has left him “more worried about Bitcoin than excited about Zcash” given the current structure of the market. According to the analyst, this exact technical signal has historically occurred right before major pullbacks in the market’s leading asset.

    Derivative Market Overheating and Volume Drop

    Technical data from CoinGlass supports these warnings of local overheating. Over a 24-hour window, Zcash trading volumes dropped significantly, with spot trading volume falling by 24.97% and derivatives volume shrinking by 24.16%. This suggests that the initial institutional excitement surrounding Zcash ETF developments has already been priced in, driving a price correction down to $779.38.

    Additionally, short-term activity in the futures market shows sharp divergence. In the four-hour timeframe, futures selling escalated rapidly, jumping by 101.68%. At the same time, leveraged trading remains highly elevated, with $1.53 billion in borrowed capital locked in Zcash margin positions. This leverage represents over 11% of the asset’s total market capitalization, which currently stands at $13.13 billion.

    Critical Views and Liquidation Risks

    The debate surrounding this rally is further intensified by commentary from Alex Thorn, the head of research at Galaxy Digital. Thorn voiced strong skepticism about the long-term viability and utility of the ecosystem. He criticized traders who chose to “pump ZEC because it’s ‘private bitcoin’” and went on to explain that account-based blockchains are “privacy nightmares” by design, arguing that they are “substantially less private than UTXO-based chains like bitcoin.”

    If the high concentration of leveraged positions—represented by the $1.53 billion futures overhang—begins to trigger forced liquidations, it could set off a domino effect across major crypto derivatives exchanges. Because Bitcoin is currently experiencing a lack of strong buying momentum within its current consolidation range, sudden panic in the derivatives space coupled with a broad liquidity drain could serve as the catalyst for a deeper market-wide correction, forcing investors to quickly transition into a risk-off posture.