This article is about Bitcoin, morality, and legality. We examine the recent Coldcard incident. We also explain how White-Hat Hackers intervened. This case brings Bitcoin, law, and morality together. It raises important questions about what is legal, what is ethical, and where the line between the two lies.

Securing your funds
Imagine renting a bank safe deposit box to store your life savings. It represents the perfect blend of total privacy and absolute security. No invasive KYC questionnaires, no tedious AML checks – just you, the vault, and your physical key. Exactly like banking was in the good old days.
The security breach
Then, the security collapses. You learn the bank made a devastating error – your key was badly cut. The flaw is so predictable that bad actors can reverse-engineer it to open your box. Worse still, news breaks that some people’s money is already vanishing from the vaults, stolen by thieves wielding replicated keys.
The rescuers
Then, an unbelievable twist occurs. A master locksmith, someone with the legendary skills of the LockpickingLawyer, discovers the flaw. He walks right into the bank, unlocks your safe deposit box using a makeshift key duplicated in his own workshop (AKA the “garage”), and empties it completely. But he isn’t stealing your wealth – he is rescuing it. To keep your money safe from actual criminals, he moves it into a secure trust account and issues a public invitation for you to claim it. The catch? To get it back, you must now navigate the very verification checks you originally tried to avoid, proving beyond a doubt that the money is yours.
This creates a massive logistical paradox: How can anyone definitively prove ownership of physical cash once it is removed from their possession?
The above story is of course fictitious. But below we will tell you about a real story, real assets (Bitcoin) and real people.
What if someone took your Bitcoin to protect it?
A Coldcard vulnerability exposed some Bitcoin wallets to attackers. White-Hats stepped in and moved more than 50 BTC into a recovery trust to prevent criminals from taking it. But there is an uncomfortable question: who authorised the rescue?
The Bitcoin had not necessarily been stolen. The owners had not necessarily consented to the intervention. Yet the White-Hats took control of their funds, and the owners must now prove ownership to recover them (and how does one prove BTC ownership anyways?).
So were the White-Hats protecting someone’s property – or taking it (some may call it a “theft”)?
What happened with Coldcard?
In July 2026, Coinkite disclosed a vulnerability affecting certain COLDCARD firmware versions. A software error weakened the randomness used to generate some wallet seeds. This created a race between three parties: the original owner, a criminal attacker, and a White-Hat researcher. Whoever moved the Bitcoin first could potentially control it. But who has the right to move someone else’s Bitcoins?
A note about VD&A and our legal assistance to unfreeze USDT
Some clients confuse our work with that of White-Hat Hackers because they believe we use similar techniques to unfreeze stablecoins. Nothing could be further from the truth.
VD&A does not access or take control of clients’ assets. We assist with the recovery of centralised assets such as USDT through purely legal channels. This includes negotiating with Tether and, where necessary, working with the relevant authorities. You can learn more about our USDT recovery services.
The White-Hats stepped in
White-Hat researchers identified vulnerable funded addresses and moved Bitcoin before criminals could take it. More than 50 BTC was reportedly secured through the rescue effort. By September 2026, 52,37 BTC had reportedly been moved into the Crypto Recovery Trust, a Wyoming trust created to safeguard the recovered funds and return them to verified owners.
The intention was clear: protect the Bitcoin first, resolve ownership later. But that creates a difficult question.
The Bitcoin had not necessarily been stolen. So when the White-Hats moved it, who gave them permission?
Protection or unauthorised custody?
Imagine you own 10 BTC in a vulnerable wallet. You have not lost it. You have not asked anyone to move it. In fact, you might have discovered the vulnerability yourself and transferred the Bitcoin the next day.
Instead, a White-Hat discovers the vulnerability first and moves your Bitcoin into a recovery trust. Your Bitcoin is now safe from criminals. But it is also no longer under your control. It is basically not yours anymore. To get it back, you have to prove that the Bitcoins are yours. This is something many Bitcoin owners wouldn’t want to go through in the first place. And that is the central dilemma.
The White-Hats may have prevented a theft. But they did so by taking control of the property themselves.
What if the owner would have acted anyway?
This is the crucial counterfactual. Suppose an owner would have moved their Bitcoin safely the next morning. A White-Hat moves it during the night though. The White-Hat prevented a possible theft, but also created a real custody situation that would never have existed otherwise.
The ownership problem
Bitcoin makes the situation even more complicated. Control of a private key proves control of a Bitcoin address. It does not necessarily prove who originally owned the funds. If a vulnerability allows an attacker and a White-Hat to reconstruct the same private key, both may be able to control the same Bitcoin.
A recovery trust therefore cannot simply ask someone to sign a message with the key and assume that person is the original owner. In this particular situation this isn’t enough. Instead, owners may need to provide additional evidence, such as transaction history, exchange records, or other proof of ownership. But are we supposed to keep such records for Bitcoin?
That creates an unusual situation:
You may have to prove that Bitcoin is yours even though you never voluntarily gave it away.
The legal question
It would be too simple to call the White-Hat intervention either legal or illegal without examining the specific facts and applicable law. The important question is whether anyone had the legal authority to take control of someone else’s Bitcoin without consent. Good intentions may matter. So may the urgency of the threat. But “I took it to protect you” does not automatically answer the question of authority.
The Safe Harbor difference
The Security Alliance’s Safe Harbor framework provides an interesting contrast. Protocols can establish rules that allow authorised White-Hats to intervene during active exploits. The participants know in advance what intervention is permitted and how recovered assets should be handled. That is very different from an individual Bitcoin owner who never agreed to such an arrangement. Prior authorisation changes the equation. And such didn’t exist in the Coldcard incident.
So, are the White-Hats heroes?
The White-Hats may have prevented criminals from stealing Bitcoin worth millions of dollars. The recovery trust was created to safeguard the funds and return them to verified owners. But the other side remains uncomfortable.
The Bitcoin had not necessarily been stolen. The owners had not authorised the intervention. Their funds were moved without their consent, and they may now have to prove ownership to get them back. In fact, they may never get it back. Or even if they do, they may need to sacrifice their privacy – something they never thought may happen with Bitcoin.
This leaves a difficult question:
When protecting someone’s property requires taking control of it, at what point does protection become possession?
Bitcoin was designed to give people control over their own money. The Coldcard incident shows what happens when that principle collides with the need to protect vulnerable users.
Were the White-Hats heroes? Or did they cross a line? You decide…