Crypto Vigilantes Target Coldcard Hacker With On-Chain Messages and Appeals
A bitcoin wallet holding about $36 million in stolen funds has become an unlikely public message board, as victims and opportunists alike send small payments to attach permanent notes for the hacker.
“You stole, please return some.”
That plea is now etched into the Bitcoin blockchain, one of many messages directed at the address linked to the Coldcard exploit. Each note is embedded in a transaction, meaning users must include a small amount of bitcoin to have their message recorded forever.
The wallet—“bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r”—has been identified by blockchain analysts, including Galaxy Research, as controlled by the attacker. Since the breach began on July 30, the address has received multiple deposits, many carrying messages. Most are appeals for the return of funds, while others are opportunistic or promotional, including at least one offering to help launder the stolen BTC.
The situation highlights a lesser-known Bitcoin feature called OP_RETURN, which allows users to embed short text within transactions. Originally intended for technical purposes like timestamping or data verification, it has also become a way for users to leave permanent messages on-chain.
The Coldcard exploit has grown into a major self-custody breach, with confirmed losses now exceeding $100 million.
The messages vary widely in tone. Some are direct pleas, such as “Please Please Please,” or requests like “80% of my 5 BTC.” It’s unclear whether these come from actual victims or from opportunists trying to take advantage of the attention.
Others are more self-serving. One message reads, “I clean btc, do kyc and cashout. I take 10%,” complete with contact details—an apparent pitch to the hacker. Another asks for “1 BTC for my Bitcoin journey,” unrelated to the theft but leveraging the wallet’s visibility.
A few messages even read like abstract poetry, including: “Monday owns my day / five plus ten bitcoin stranger / let me call in free.”
This isn’t the first time OP_RETURN has been used this way. After the 2020 LuBian mining pool hack, operators used similar messages to contact the attacker and attempt negotiations, leaving traces that later helped analysts identify related wallets.
What makes this case different is the scale and open participation. Instead of a single entity reaching out, a mix of victims, opportunists, and observers are using the blockchain as a permanent canvas for pleas, pitches, and digital graffiti.
Share this content:













