A Bitcoin wallet linked by blockchain researchers to the Coldcard hacker has become a public message board, with users sending small payments that include written notes on-chain. According to CoinDesk, the address holds roughly $36 million in stolen bitcoin and has received several deposits since the Coldcard theft began on July 30.
The development matters because it shows how crypto security incidents can spill into public blockchain space, where victims, observers and opportunists can all interact with an attacker’s address in a visible and permanent way. It also adds another layer of attention to a self-custody breach that CoinDesk said has confirmed losses topping $100 million.
The messages were attached using Bitcoin’s OP_RETURN function, which allows a small text string to be included in a transaction. Developers commonly use the feature for timestamping documents or embedding compact proofs, but in this case it has become a tool for public appeals and solicitation.
Some notes appear to ask for stolen funds to be returned, including one that says, “You stole, please return some.” Others are less direct or more opportunistic, including a message offering to help launder the stolen bitcoin for a 10% cut and another unrelated request for 1 BTC.
CoinDesk noted that this is not the first time OP_RETURN has been used to contact a thief. During the 2020 LuBian mining pool theft, operators used similar blockchain messages in an attempt to reach the attacker, and those messages later helped analysts distinguish wallets associated with LuBian from attacker-controlled wallets.