Victims Pay to Leave Messages on Coldcard Hacker’s Bitcoin Wallet

Binance
Blockonomics


TL;DR

  • The Coldcard hacker’s wallet, holding around $36 million in stolen bitcoin, has been receiving permanent messages via OP_RETURN since July 30.
  • The notes range from victim pleas asking for funds to be returned, to money laundering offers and requests unrelated to the theft.
  • The Coldcard exploit has accumulated confirmed losses exceeding $100 million, making it one of the largest breaches in the history of self-custody.

The wallet linked to the Coldcard hacker became an unwilling public mural on the Bitcoin blockchain. Since July 30, when the hardware wallet exploit began, the address “bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r”, identified by Galaxy Research investigators as one of those controlled by the attackerreceived multiple deposits accompanied by written messages. Each arrives with a real, though minimal, payment and is permanently recorded in Bitcoin’s public ledger.

The mechanism behind this dynamic is OP_RETURN, a native protocol function that allows a string of text to be attached to any transaction. The text is permanently inscribed on the blockchain alongside the monetary transfer. Originally designed for developers to timestamp documents or embed small proofs, the function also allows personal use, such as leaving notes directed at a specific address.

coldcard hacker exploit bitcoincoldcard hacker exploit bitcoin

Ledger

An Unlikely Mural on Coldcard

The messages tracked by Arkham Intelligence reveal a very broad spectrum of intentions. Some are genuine in their desperation: “You stole, please give something back” or “Please, please, please” accompanied by a return address. Another message directly demands 80% of 5 BTC lost. Verifying whether these senders are actually victims of the hack or simply opportunists riding a wave of sympathy is impossible from the outside.

Other messages bear no relation to the theft whatsoever. One offers BTC laundering services at a 10% fee and includes a Telegram username, betting on recruiting the hacker as a client. Another simply asks for “1 BTC for my journey into Bitcoin,” with no connection to the exploit. There is even one that reads like abstract poetry: “Monday owns my day / five plus ten bitcoin I miss / let me call in freedom.”

HackersHackers

OP_RETURN: A Negotiation Tool

This is not the first time this function has been used to attempt contact with a thief. During the LuBian mining pool robbery in 2020, where more than 127,000 BTC vanished, traders turned to OP_RETURN to negotiate with the attacker. Those messages later became useful evidence for analysts trying to identify which wallets belonged to the pool and which to the attacker. In the case of Coldcard, the difference is that those writing are not an organization but a scattered crowd: victims, opportunists, and the curious, all immortalizing their words in the world’s most censorship-resistant ledger.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*