Finst

Coldcard Hacker Wallet Gets Bitcoin Graffiti From Victims

Victims are using OP_RETURN to address the suspected hacker directly on the Bitcoin blockchain. According to Galaxy Research, the wallet is linked to the Coldcard attack and holds about $36 million.

Coldcard Hacker Wallet Gets Bitcoin Graffiti From Victims

Key Takeaways

  • A wallet linked to the Coldcard hacker has been getting a stream of small Bitcoin deposits with messages on the blockchain since July 30.
  • The messages were sent through OP_RETURN and ranged from pleas and poetry to an offer to launder stolen BTC for 10 percent.
  • The wallet now holds about $36 million, while the incident is also sparking debate about data use and network congestion on Bitcoin.

A wallet tied to the Coldcard hacker has been receiving a steady flow of tiny deposits with messages on the Bitcoin blockchain since July 30. The notes range from pleas and poetry to an offer to launder the stolen BTC for 10 percent, and the wallet itself now holds about $36 million (€31.3 million) in assets.

Messages on the Blockchain

The wallet, bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, has been flagged by blockchain researchers, including Galaxy Research, as one of the addresses connected to the attack. The messages are being sent through OP_RETURN, a Bitcoin feature that allows users to attach small pieces of data to a transaction. That makes the message permanently visible on the blockchain, even though the bitcoin attached to it cannot be spent.

One message reads, "You stole, please return some." Others are more indirect and almost theatrical, including one that comes across like abstract poetry. In each case, the sender still has to pay a small amount of BTC just to leave the message behind.

More Than Just a Hack

The wave of messages shows how a hack on Bitcoin can quickly turn into a public, onchain spectacle. Victims use it to speak straight to the attacker, while others treat the same channel as a place for jokes, pitches, or even criminal offers. The end result is a kind of blockchain graffiti wall, except the messages are permanent transactions instead of spray paint.

OP_RETURN is nothing new, and it has been a point of debate in the Bitcoin community for years. The feature was standardized in Bitcoin Core 0.9.0 in 2014 so data could be embedded without bloating the UTXO set. Supporters say it is a practical way to store small amounts of data onchain, while critics argue it can add network strain and push fees higher.

Why It Matters

For European crypto readers, the bigger point is that Bitcoin security incidents do more than just move stolen coins around. The way OP_RETURN is being used also feeds into wider arguments about data storage, network congestion, and how much information should really live on the blockchain. So this is not just a hack story, but also a reminder of the technical tradeoffs built into Bitcoin. A similar aftermath played out in the Coldcard flaw, where hundreds of wallets were drained in a short time after a problem with key generation.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.