A Bitcoin address linked to the ongoing Coldcard theft has turned into an open, permanent message board, according to a report published August 4 by blockchain-intelligence firm Arkham Intelligence. Alongside tracking the stolen funds, on-chain analysts are now watching a stream of text messages sent directly to the wallet, written into the blockchain itself, where they will remain visible indefinitely.
The messages are being attached using OP_RETURN, a standard Bitcoin function that lets users add a small amount of arbitrary data to a transaction. Because that data is recorded on-chain, anyone can send a note to any address, including one holding stolen coins, and it becomes a permanent part of Bitcoin’s public ledger. The result, in this case, is a running log of how people are responding to one of the largest self-custody thefts in Bitcoin’s history so far.
What Is Being Sent, and Where to See It
The messages Arkham documented span several distinct types. Some are appeals from what appear to be victims or sympathizers asking the holder to return the coins, such as “You stole, please return some,” “Please Please Please,” etc. Others are unrelated requests for money from strangers hoping the address’s controller might share the proceeds. A few are simply poems or aphorisms about theft. And at least one message is a solicitation from a third party offering money-laundering services in exchange for a cut — a note that, by its own terms, describes a criminal offer, and which authorities monitoring the address can now see as plainly as anyone else.
Arkham linked the messages to individual transactions on its block explorer, allowing anyone to inspect the underlying on-chain data. The address at the center of the activity, and the specific transactions carrying the messages, can be viewed directly:
- The hacker-linked address: bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r (confirmed by Arkham & Galaxy Research)
- A message requesting Bitcoin from the address’s controller: transaction bb5936c0…
- A plea referencing theft and asking for the return of funds: transaction cf437e6f…
- A short poem written into the ledger: transaction ce92807c…
- An aphorism about theft: transaction cadc03ba…
The Crypto Times has chosen not to reproduce the full text of the money-laundering solicitation or its contact details, as doing so would republish an offer to commit a crime.
How to View the Messages Yourself
Per Arkham’s guide, the activity can be monitored in real time on a block explorer. On Arkham, a user can search the hacker-linked address, scroll through its incoming transactions, and expand a transaction’s details to read the OP_RETURN data attached to it. The same information is visible on other Bitcoin explorers, since OP_RETURN data is public by design.
It is worth noting that these are inbound messages: sending an OP_RETURN note to an address does not move or affect the coins it holds, and none of this activity changes the status of the stolen funds.
What the Messages Do, and Don’t, Change
The phenomenon is a byproduct of Bitcoin’s transparency rather than a development in the case itself. The stolen coins remain where they were; Galaxy Research has said roughly 90% of the Bitcoin taken across the confirmed waves has not moved, and the funds are being tracked by investigators who have shared attacker addresses with law enforcement and exchanges.
For observers, the message board offers an unusual, real-time view of the social reaction to a major theft playing out on a public ledger, a mix of grief, opportunism, and dark humor recorded permanently on-chain.
For victims, it changes nothing about recovery, which continues to depend on law enforcement and the traceability of the coins rather than on these messages. Arkham noted that the same OP_RETURN technique has featured in past investigations, including one case its analysts examined that was ultimately traced to an insider.
Background: The Coldcard Exploit
The messages stem from an exploit that has drained an estimated $100 million or more in Bitcoin, up to roughly $130 million including suspected activity, from wallets created on certain Coldcard hardware devices. The root cause was a March 2021 firmware flaw that generated recovery seeds with too little randomness, leaving the underlying keys reproducible without any access to the physical device.
Galaxy Research has said the exploit is ongoing and now involves at least 15 independent attackers, and Coldcard’s manufacturer, Coinkite, has urged all affected users to move their funds to a wallet built from a new seed.
Also Read: Coldcard Hack Stirs Dormant Bitcoin, Retail Transfers Hit FTX-Era Highs
