NewsCryptoColdcard Hacker's $36 Million Bitcoin Wallet Becomes a Blockchain Message Board of Pleas and Hustles

Coldcard Hacker's $36 Million Bitcoin Wallet Becomes a Blockchain Message Board of Pleas and Hustles

Author: Coindesk·

Key Takeaways

  • The Coldcard hardware wallet exploit, detected on July 30, has resulted in confirmed losses exceeding $100 million.
  • A Bitcoin wallet tied to the attacker holding roughly $36 million in stolen funds has attracted public messages embedded via Bitcoin's OP_RETURN function.
  • Messages sent to the wallet include victim pleas for restitution, solicitations for money-laundering services, and unrelated donation requests.
  • Coldcard is manufactured by Coinkite and was marketed specifically to security-conscious users for its air-gapped signing design, making the breach particularly significant for the self-custody ecosystem.
  • The use of OP_RETURN to communicate with suspected thieves is not unprecedented, as similar on-chain messages were sent during the 2020 LuBian mining pool theft involving over 127,000 BTC.
Coldcard Hacker's $36 Million Bitcoin Wallet Becomes a Blockchain Message Board of Pleas and Hustles

Coldcard Hacker's $36 Million Bitcoin Wallet Becomes a Blockchain Message Board of Pleas and Hustles

A Bitcoin wallet tied to the Coldcard hardware wallet hacker — currently holding approximately $36 million in stolen funds — has become an impromptu public message board, as hack victims and opportunists alike pay to etch permanent notes into the blockchain addressed to the thief.

The wallet, identified as bc1qq85v2c926eg6pgxh7lf6cnsz80qs3fcu9r, has been confirmed by blockchain researchers at Galaxy Research as one of the attacker-controlled addresses linked to the theft. Since the Coldcard exploit first surfaced on July 30, the address has received a stream of small deposits, many carrying text messages attached via Bitcoin's OP_RETURN function.

The messages range from heartfelt appeals for restitution to outright solicitations. One simply reads: "You stole, please return some." Another pleads: "Please Please Please." A more direct message asks for "80% of my 5 BTC" back. Whether these originate from genuine victims or from opportunists riding a wave of public sympathy is difficult to verify.

How OP_RETURN Turns the Blockchain Into a Bulletin Board

The mechanism behind these messages is a built-in Bitcoin feature known as OP_RETURN, which allows any user to append a short text string to a transaction. Once included, the text is permanently timestamped and recorded on the blockchain alongside the transfer of funds — visible to anyone, erasable by no one.

While OP_RETURN was designed for technical use cases — such as timestamping documents or embedding cryptographic proofs — it has long been repurposed by individuals to leave personal notes, political statements, and even marriage proposals. Each message requires a real, if minimal, bitcoin payment to be included. The feature has become a well-known cultural outlet within the Bitcoin ecosystem, with users routinely embedding messages tied to major events, from political slogans to memorials — a practice that has only grown as on-chain inscription tools have made the process more accessible to non-technical users.

Opportunists and Hustlers Join the Chorus

Not every message is a plea. Some are brazen business pitches. One user offered money-laundering services directly to the hacker, writing: "I clean btc, do kyc and cashout. I take 10%," along with a Telegram handle. Another message — "1 BTC for my Bitcoin journey" — appears wholly unrelated to the hack, with the sender seemingly leveraging the wallet's public visibility to solicit donations from strangers.

One message reads almost like abstract poetry: "Monday owns my day / five plus ten bitcoin stranger / let me call in free." On-chain analytics platform Arkham Intelligence has surfaced several of these transactions, making them publicly traceable.

A representative transaction can be viewed on mempool.space.

A Growing Self-Custody Breach

The Coldcard hardware wallet exploit, first detected on July 30, has escalated into a significant self-custody security incident. Confirmed losses from the breach now exceed $100 million, according to reporting by CoinDesk. The scale of the theft has drawn attention to vulnerabilities in hardware wallet security and the broader implications for self-custody in the cryptocurrency ecosystem.

Coldcard, manufactured by Coinkite, is a Bitcoin-only hardware wallet marketed specifically to security-conscious users for its air-gapped signing design — a feature intended to keep private keys isolated from internet-connected devices. A breach of a device positioned as a top-tier self-custody solution raises questions about the assumptions underpinning hardware wallet security more broadly, particularly as the industry has long promoted cold storage as the gold standard for protecting large cryptocurrency holdings.

Not the First Time OP_RETURN Has Been Used to Contact a Thief

The phenomenon of using OP_RETURN to communicate with a suspected attacker is not unprecedented. During the 2020 LuBian mining pool theft — in which more than 127,000 BTC vanished — the pool's operators used OP_RETURN messages to reach out to the attacker and attempt to negotiate the return of the funds. Those on-chain communications later served as a key data point for analysts seeking to distinguish between wallets controlled by LuBian and those controlled by the attacker.

What sets the Coldcard situation apart is the nature of the outreach. Rather than a single party attempting to negotiate, the Coldcard hacker's wallet has attracted a crowd: genuine victims seeking recovery, opportunists pitching services, and random individuals seeking attention — all paying to immortalize their words on Bitcoin's permanent public ledger.