Loading market data...
Back to Feed
BITCOIN

"You stole, please return some." Coldcard hacker's wallet becomes a graffiti wall of pleas and hustles

Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for "You stole, please return some." Coldcard hacker's wallet becomes a graffiti wall of pleas and hustles
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$36 million$100 million

Summary

Since July 30, 2026, a Bitcoin wallet tied to the Coldcard hardware wallet hacker has received multiple deposits containing messages via Bitcoin’s OP_RETURN function. These messages include pleas for the hacker to return stolen funds, offers to launder the cryptocurrency for a cut, and various other personal or opportunistic notes. The wallet currently holds about $36 million in stolen funds linked to a breach that has resulted in losses exceeding $100 million.

Why it matters

This development highlights both the scale of the Coldcard breach and how Bitcoin’s OP_RETURN feature allows users to communicate directly with the hacker on the blockchain. It reflects new social and technical dynamics where victims and others use blockchain's immutability to send public appeals or solicitations, creating a unique form of interaction with criminal actors in the crypto space.

Key context

The Coldcard hardware wallet exploit is a major self-custody security incident detected on July 30, causing substantial financial loss. The OP_RETURN script in Bitcoin transactions enables users to embed small text messages permanently on the blockchain, initially intended for technical proofs or timestamping. Past incidents, such as the 2020 LuBian mining pool theft, also saw OP_RETURN employed to message hackers, but the Coldcard messages come from a broader crowd with mixed motives.

Key numbers and entities

The hacker-controlled Bitcoin address is bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, with roughly $36 million in funds. Confirmed overall losses from the Coldcard breach now exceed $100 million. Blockchain research organizations involved include Galaxy Research and Arkham Intelligence. Several Bitcoin messages contain pleas and pitches, including one offering laundering services for a 10% fee.

What remains unclear

The source does not clarify whether the messages originate from genuine victims or opportunistic parties. It also remains uncertain if the hacker will respond to any of the appeals or offers. No information is provided about any ongoing efforts to recover the stolen funds or the attacker’s identity beyond wallet attribution.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]