A bitcoin wallet holding around $36 million in stolen funds has turned into an unlikely public billboard, with victims and opportunists paying small amounts to leave permanent messages for the thief.
“You stole, please return some.”
That plea is now embedded on the Bitcoin blockchain, one of several notes directed at the address linked to the Coldcard exploit. Each message is included in a transaction, meaning senders attach a small payment to ensure their words are recorded forever.
The wallet—“bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r”—has been identified by blockchain analysts, including Galaxy Research, as controlled by the attacker. Since the hack began on July 30, the address has received multiple deposits, many containing written messages. Most ask for funds to be returned, while others are opportunistic or promotional, including at least one offering laundering services.
The situation highlights a niche Bitcoin feature known as OP_RETURN, which allows users to embed short text into transactions. Originally designed for technical purposes like timestamping data, it also enables users to leave permanent notes on the blockchain.
The Coldcard exploit has since grown into a major self-custody breach, with confirmed losses exceeding $100 million.
The messages themselves range widely. Some are simple appeals, like “Please Please Please,” or requests such as “80% of my 5 BTC.” It’s unclear whether all are from actual victims or from people trying to capitalize on the situation.
Others are clearly opportunistic. One message advertises, “I clean btc, do kyc and cashout. I take 10%,” including contact details—an apparent pitch to help the hacker move funds. Another asks for “1 BTC for my Bitcoin journey,” unrelated to the theft but leveraging the wallet’s visibility.
A few messages even read like abstract verse, including: “Monday owns my day / five plus ten bitcoin stranger / let me call in free.”
This isn’t the first time OP_RETURN has been used this way. After the 2020 LuBian mining pool hack, operators used similar messages to reach out to the attacker and negotiate, leaving traces that later helped analysts identify wallets.
What makes the Coldcard case different is the scale and participation. Instead of a single entity trying to contact the hacker, a broad mix of users—victims, opportunists, and onlookers—are using the blockchain as a permanent canvas for pleas, pitches, and digital graffiti.





