All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard hacker's wallet flooded with pleas and laundering offers via Bitcoin messages

Created at 5 Aug · 5:21 AM1 source↑ Market-relevant
IN SHORT

A wallet linked to the Coldcard hacker has become a public message board, receiving small Bitcoin deposits with attached messages. These range from desperate pleas for stolen funds to offers to launder the illicit gains.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$36 millionfunds in hacker's wallet
10%laundering fee offered
5 BTCamount requested in one plea
1 BTCamount solicited unrelated to hack
127,000 BTCstolen in LuBian mining pool theft
$100 millionconfirmed losses from Coldcard exploit

Who's Involved

Coldcard hacker
recipient of pleas and offers on Bitcoin blockchain
Galaxy Research
blockchain researchers identifying attacker-controlled addresses
Arkham Intelligence
on-chain tracker noting various messages
LuBian mining pool
victim of a 2020 theft using similar messaging tactics
Coldcard hacker's wallet flooded with pleas and laundering offers via Bitcoin messages

↳ Why This Matters

The use of Bitcoin's OP_RETURN function to communicate with a hacker highlights the transparency of the blockchain and the creative, albeit unconventional, ways individuals attempt to interact with illicit actors and recover stolen assets.

Key facts

  • A wallet associated with the Coldcard hacker has received numerous small Bitcoin deposits with embedded messages.
  • These messages are permanently recorded on the Bitcoin blockchain via the OP_RETURN function.
  • The messages include pleas from victims to return stolen funds and offers from third parties to launder the money.
  • The Coldcard exploit has resulted in confirmed losses exceeding $100 million.

A wallet linked to the individual responsible for the recent Coldcard exploit has become a public forum for communication, with users attaching messages to small Bitcoin deposits. These transactions, utilizing Bitcoin's OP_RETURN function, permanently inscribe sentiments onto the blockchain. The messages range from desperate pleas from victims seeking the return of their stolen funds to opportunistic offers from individuals proposing to launder the illicit gains for a fee. The wallet currently holds approximately $36 million in cryptocurrency. Blockchain researchers, including those from Galaxy Research, have identified the address as belonging to the Coldcard attacker. Since July 30, numerous transactions have carried these messages, with some users directly requesting specific amounts of Bitcoin back, while others use the platform for unrelated solicitations or abstract notes. This method of communication via OP_RETURN is not unprecedented, having been employed during the 2020 LuBian mining pool theft to attempt contact with the perpetrators. The Coldcard exploit itself has led to confirmed losses exceeding $100 million.

Frequently asked questions

OP_RETURN is a Bitcoin transaction script that allows users to attach a small amount of data, such as text messages, to a transaction. This data is permanently recorded on the blockchain.

Confirmed losses from the Coldcard exploit have surpassed $100 million.

Yes, a similar tactic was used during the 2020 LuBian mining pool theft, where operators embedded messages in transactions to contact the attacker.

What Happens Next

01The hacker may respond to messages or continue to hold the stolen funds.
02Further analysis of the blockchain may reveal additional messages or patterns of activity.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A wallet tied to the Coldcard hacker began receiving deposits with attached messages on July 30.
Messages are embedded in Bitcoin transactions using the OP_RETURN function, permanently recorded on the blockchain.
The messages include pleas for stolen money, offers to launder funds for a 10% fee, and unrelated solicitations.
This tactic has been used previously, notably during the 2020 LuBian mining pool theft.

Sources

T1
"You stole, please return some." Coldcard hacker's wallet becomes a graffiti wall of pleas and hustlesCoinDesk

Related Stories

Coldcard Urges Users to Move Bitcoin Amid Exploit
4 Aug · 11:00 AM
At least 15 attackers exploited Coldcard vulnerability, Galaxy Digital says
4 Aug · 2:46 PM
Ledger: Coldcard Exploit Highlights Need for AI-Resistant Bitcoin Wallet Security
4 Aug · 9:21 PM
BitGo to switch WBTC cross-chain provider from LayerZero to Chainlink
4 Aug · 1:06 PM
Mystery group Crypto Watchdog targets digital assets in Washington ads
4 Aug · 1:06 PM