'You stole, please return some.' Coldcard hacker's wallet becomes a graffiti wall of pleas and hustles
A bitcoin wallet tied to the Coldcard hardware wallet hack, holding roughly $36 million, has become an unlikely message board where victims and opportunists pay to leave OP_RETURN notes for the thief.
Intelligence analysis by Llama

Since the Coldcard exploit began on July 30, victims and hustlers have been paying tiny amounts of bitcoin to leave permanent messages on the attacker's $36M wallet using Bitcoin's OP_RETURN function. Pleas to return funds sit alongside laundering pitches and unrelated pleas for handouts.
Someone stole a giant pile of bitcoin, and because every bitcoin payment can carry a tiny note attached to it, lots of people are sending the thief tiny payments just to write messages on the public record. Some are begging for their money back, others are trying to get hired to clean the stolen coins, and a few are just being weird. The thief now owns the world's most expensive chalkboard.
Analysis
A $36M Billboard Nobody Asked For
Once blockchain researchers at Galaxy and Arkham tagged the attacker's address, the wallet stopped being a private stash and became a stage. Every deposit, no matter how small, comes with an attached OP_RETURN string that lives on the chain forever. Most of the messages are raw pleas — "Please Please Please," "You stole, please return some," one victim asking for "80% of my 5 BTC" — but the wallet is also being used as a free classifieds section. A self-styled launderer is offering to "clean btc, do kyc and cashout" for a 10% cut, complete with a Telegram handle; another sender is just begging strangers for "1 BTC for my Bitcoin journey." The hacker, in effect, now co-runs the most expensive PO box in crypto, whether they wanted to or not.
OP_RETURN Wasn't Built for This
The messages are riding on a quirk of Bitcoin's scripting language that lets any transaction embed up to roughly 80 bytes of arbitrary data. Developers typically use OP_RETURN for timestamping documents, embedding proofs, or anchoring sidechain data; the field burns the value of any BTC sent there so it can never be spent again. The Coldcard saga shows what happens when a purely technical feature collides with human emotion: grief, opportunism, and a few touches of accidental poetry ("Monday owns my day / five plus ten bitcoin stranger / let me call in free") all end up immortalized on the same ledger that records the theft itself. It is a textbook example of how Bitcoin's public, append-only nature turns every wallet into a billboard the moment it is doxxed.
The Coldcard Breach Is Bigger Than the Graffiti
Zoom out and the graffiti is the lighter side of a much darker story. The Coldcard hardware wallet exploit, first detected on July 30, has been confirmed to have drained more than $100 million from users who trusted the device for self-custody. Coldcard has historically positioned itself as a high-security, air-gapped option for bitcoiners, and a supply-chain or firmware-level breach of that reputation is a body blow to the segment. The OP_RETURN chatter is mostly catharsis, but it also functions as a low-cost early-warning system: anyone tracking the attacker's addresses can now watch incoming deposits in real time, mapping which victims are still hoping for a refund and which "helpers" are circling the drain. If the hacker ever does try to move the loot, that same public ledger will make it harder, not easier, to cash out cleanly.
Key points
- Wallet bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r holds roughly $36M in bitcoin linked to the Coldcard hardware-wallet hack.
- Senders have been attaching OP_RETURN messages to small deposits, asking for refunds, offering laundering services, or simply soliciting money.
- The Coldcard exploit first detected on July 30 has driven confirmed losses above $100 million.
- Galaxy Research and Arkham Intelligence have publicly tagged the address as attacker-controlled.
- The OP_RETURN chatter echoes the 2020 LuBian case, where the mining pool used the same trick to try to negotiate with its thief.
- The incident underscores how public blockchains turn any doxxed wallet into a permanent public canvas.
If the unusual level of public attention pressures the attacker, partial voluntary refunds remain possible, as has happened in past high-profile crypto heists. The relentless pings from victims and researchers also raise the operational cost of cashing out, which could push the hacker toward negotiated restitution.
The graffiti is unlikely to recover funds; the attacker can simply ignore the messages, and the constant pings do nothing to slow movement of the underlying coins. More worrying, the Coldcard exploit topping $100 million in losses is a serious blow to confidence in hardware-wallet self-custody and could trigger broader scrutiny of supply-chain security across the segment.



