“You stole, please return some.”
That sentence is now a permanent entry on the Bitcoin blockchain. It’s addressed to the wallet linked to the Coldcard hacker, an address currently sitting on roughly $36 million. And whoever wrote it paid a real, if tiny, fee to put it there.
The address is “bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.” Blockchain researchers, including the team at Galaxy Research, have flagged it as one of the attacker-controlled addresses tied to the theft.
Since the Coldcard theft started on July 30, that address has taken in a string of deposits, and a lot of them come with text attached.
What people are actually writing
Most of the messages are pleas to give the money back. Some are performative. At least one is a business pitch to launder the stolen BTC.
According to on-chain tracker Arkham Intelligence, the opening plea isn’t a one-off. One message reads “Please Please Please” next to an address. Another skips the sentiment entirely and asks for “80% of my 5 BTC” back.
Whether those came from people who genuinely lost coins or from opportunists surfing the sympathy wave is hard to verify. That’s the problem with a public ledger as a message board. Anyone can write anything, and paying a few cents in fees doesn’t make you a victim.
Then there’s the openly transactional stuff. “I clean btc, do kyc and cashout. I take 10%,” one message reads, with a Telegram handle attached. That’s a laundering service cold-calling the hacker, on-chain, in public, forever.
Another has nothing to do with the hack at all: “1 BTC for my Bitcoin journey.” The sender appears to be panhandling off the attention the wallet is getting.
And one reads like it wandered in from a poetry workshop: “Monday owns my day / five plus ten bitcoin stranger / let me call in free.”
The feature that makes this possible
None of this is a hack of a hack. It’s a Bitcoin feature called OP_RETURN, which lets anyone bolt a small text string onto a transaction. The text gets timestamped into the chain permanently, right alongside the money moving.
It exists for technical reasons. Developers mostly use it to timestamp documents or embed small proofs. But nothing stops you from using that same field to leave a personal note, which is exactly what’s happening here.
So the mechanics are mundane. The scene is not. Hack victims are paying money to send messages to the person who took their money, and the network dutifully files each one away for good.
How big the underlying breach is
The Coldcard hardware wallet exploit was first detected on July 30. It’s since grown into a major self-custody breach, with confirmed losses now topping $100 million.
That $36 million sitting in the tagged wallet is a fraction of the total. Which helps explain the volume of traffic hitting it.
This has happened before, but not like this
Using OP_RETURN to talk to a thief isn’t new. During the 2020 LuBian mining pool theft, when more than 127,000 BTC vanished, the pool’s operators used OP_RETURN messages to try to reach the attacker directly and negotiate a return.
Those messages ended up serving a second purpose. Analysts later used them as one data point to help work out which wallets belonged to LuBian and which belonged to the attacker.
The difference now is who’s doing the writing. LuBian was one operator with a clear ask. The Coldcard wallet is getting a crowd: some of them victims, some of them hustlers, all of them carving their message into the ledger where it can’t be deleted.
If you want a snapshot of what a nine-figure self-custody failure looks like from the inside, it isn’t the loss figures. It’s a stranger paying a transaction fee to write “Please Please Please” at a thief who will almost certainly never write back.