“You stole, please return some.”
That message is now sitting permanently on the Bitcoin blockchain, one of several addressed to the wallet tied to the Coldcard hacker. The wallet currently holds funds worth roughly $36 million. And every one of those messages arrived with a real payment attached, however small.
The address is “bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.” Blockchain researchers, including those at Galaxy Research, have identified it as one of the attacker-controlled addresses tied to the theft.
Since the Coldcard theft began on July 30, the address has taken in several deposits, many of them carrying written messages. Most are pleas to return the stolen money. Others are performative. At least one is a sales pitch, offering to launder the stolen BTC.
Why you can write on a stranger’s wallet at all
The messages exist because of a quirky Bitcoin feature called OP_RETURN, which lets anyone attach a small text string to a transaction. The text gets permanently timestamped into the blockchain alongside the transfer of money.
The function exists for technical purposes. Developers mainly use it to timestamp documents or embed small proofs. But nothing stops users from leaving personal notes instead, and that’s exactly what’s happening here.
So this is as much a story about how the Bitcoin blockchain functions as it is about hack victims paying money to tell the person who robbed them how they feel.
The breach behind the messages
The Coldcard hardware wallet exploit was first detected on July 30. It has since snowballed into a major self-custody breach, with confirmed losses now topping $100 million.
That scale explains the volume of traffic hitting the attacker’s address. When your hardware wallet, the thing you bought specifically so you wouldn’t have to trust an exchange, is the point of failure, the recovery options thin out fast. Writing on the blockchain is what’s left.
Reading the wall
The plea that opened this story isn’t the only one. Several similar messages have surfaced, according to on-chain tracker Arkham Intelligence.
One reads “Please Please Please” alongside an address. Another bluntly asks for “80% of my 5 BTC” back, which reads less like a demand and more like a negotiation opening.
Whether these come from genuine hack victims or opportunists capitalizing on the sympathy wave is difficult to verify. That’s the uncomfortable part of an open ledger: anyone can write anything, and the chain doesn’t care who’s telling the truth.
The hustlers showed up too
Some of the messages aren’t sympathetic at all.
One reads, “I clean btc, do kyc and cashout. I take 10%,” complete with a Telegram handle. That’s a laundering pitch, sent on-chain, hoping to land the hacker as a client.
Another begs, “1 BTC for my Bitcoin journey,” which has nothing to do with the hack at all. The sender appears to be using the attention on the hacker’s wallet to panhandle strangers.
And one message reads like abstract poetry: “Monday owns my day / five plus ten bitcoin stranger / let me call in free.”
It’s happened before, but not like this
Using OP_RETURN to message a thief isn’t new.
During the 2020 LuBian mining pool theft, in which more than 127,000 BTC vanished, the pool’s operators used OP_RETURN messages to try to contact the attacker directly and negotiate a return.
Those messages ended up serving a second purpose. Analysts later used them as one data point to help confirm which wallets belonged to LuBian and which belonged to the attacker.
The Coldcard situation is different in an important way. LuBian was one operator negotiating with one thief. Here it’s a crowd: some hack victims, some opportunists, all of them immortalizing their messages on a ledger that will outlast the story.
If you want to see what a $100 million self-custody failure looks like from the inside, don’t read the incident reports. Pull up bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r and read the transaction messages in order. The desperation, the grifting and the haiku are all right there, paid for in satoshis, permanent.