The bitcoin wallet holding the proceeds of the Coldcard hardware wallet exploit has taken on an unusual second life: a public message board that victims and opportunists alike are paying to write on. The address, identified by blockchain researchers including Galaxy Research as bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, currently holds an estimated $36 million in stolen bitcoin, and it has been flooded with small transactions carrying text messages embedded through Bitcoin's OP_RETURN function since July 30.
OP_RETURN lets anyone permanently timestamp a short string of text to the blockchain alongside a transaction, and in this case that has turned the thief's own address into graffiti wall. One of the earliest and most direct entries simply reads, "You stole, please return some." Others follow the same tone: "Please Please Please," paired with a return address, and "80% of my 5 BTC," a plea from someone asking for a partial refund of a 5 BTC balance.
Not every message is a genuine appeal. Alongside the victims' pleas, opportunists have used the wallet's sudden visibility to pitch services and unrelated causes. One message reads, "I clean btc, do kyc and cashout. I take 10%," a laundering solicitation complete with a Telegram handle. Another simply asks for "1 BTC for my Bitcoin journey," with no connection to the hack at all. A few entries lean poetic rather than transactional, including one that reads: "Monday owns my day / five plus ten bitcoin stranger / let me call in free."
How the theft unfolded
The messages are a strange coda to what has become one of the largest self-custody breaches on record. Coinkite, the maker of the Coldcard hardware wallet, notified users in late July that a flaw in older firmware had compromised certain devices. According to reporting from TheHackerNews and other outlets tracking the incident, an attacker drained 1,196 addresses in just 41 minutes on July 30, extracting roughly 1,082.65 BTC worth about $70.2 million at the time.
The losses kept climbing in the days that followed as more compromised wallets were swept. By August 2-3, the total reached roughly 1,367 BTC, or about $89 million, pulled from 4,585 addresses, and industry trackers now put cumulative losses above $130 million. Researchers traced the root cause to a March 2021 firmware build that mistakenly routed seed generation to a deterministic software pseudorandom number generator instead of the device's dedicated STM32 hardware random number generator, a flaw affecting certain Coldcard Mk2 and Mk3 units. Coinkite has urged affected users to update their firmware and migrate funds to freshly generated seed phrases.
Why it matters
The scale of the theft has rattled a segment of the bitcoin community that treats cold storage as the gold standard of security, precisely because it keeps private keys offline and away from internet-connected threats. A flaw baked into firmware for roughly five years before detection undercuts that assumption directly, and some commentators have suggested the episode could nudge cautious holders toward custodial alternatives like spot bitcoin ETFs instead of self-custody hardware.
Related: MEXC Perluas Guardian Fund Jadi $500 Juta Usai Insiden Keamanan Coldcard
Exchanges have also felt pressure to respond publicly to the fallout. MEXC expanded its own guardian fund to $500 million in the wake of the Coldcard incident, part of a broader push by trading platforms to reassure users that custodial safeguards remain in place even as confidence in some hardware-based self-custody solutions wavers.
For now, the hacker's wallet sits untouched beyond the incoming dust transactions, its balance still holding around $36 million as pleas, hustles and one-liners keep arriving on top of it, permanently etched into the bitcoin blockchain regardless of whether the thief ever reads them.