A Bitcoin address linked by blockchain researchers to the attacker behind the Coldcard theft has become an unusual public message board. Since July 30, the wallet holding roughly $36 million in stolen bitcoin has received multiple small deposits carrying text messages embedded on the Bitcoin blockchain.
Those notes, added through Bitcoin’s OP_RETURN feature, range from requests to return the money to blunt offers to help move or cash out the funds. Because the messages are written on-chain, they are publicly visible and permanent.
A wallet tied to the theft draws attention
The address has been identified by researchers as one of the wallets controlled by the party behind the Coldcard hack. As attention around the stolen funds grew, outside senders began using tiny transactions to reach the address directly.
What emerged was less a private line of contact than a public wall of commentary. Victims, bystanders, and would-be intermediaries all appeared to use the same mechanism to attach messages to payments sent to the wallet.
Messages range from appeals to criminal pitches
Some of the notes are straightforward pleas asking for at least part of the bitcoin to be returned. Others are more theatrical or poetic in tone, while some have little to do with the theft itself.
More concerning are the messages that explicitly offer services to launder or cash out the stolen BTC. One message cited in the report proposed helping move the funds for a 10% cut, showing how quickly a high-profile theft can attract opportunists as well as victims trying to make contact.
How OP_RETURN turns transactions into statements
The messages were attached using OP_RETURN, a Bitcoin function that allows small amounts of data to be embedded in a transaction. In practice, that means a sender can pay a small amount and add text that becomes part of the blockchain record.
In this case, the feature turned a wallet associated with stolen funds into a visible archive of reactions, requests, and hustles. Rather than changing control of the bitcoin, the incoming transactions mainly served to leave a traceable statement for anyone monitoring the address.
What is confirmed so far
The confirmed facts are narrow but notable: the wallet tied to the Coldcard attacker holds about $36 million in stolen bitcoin, and it has received several message-bearing deposits since July 30. Those messages include both requests for the funds to be returned and offers to help conceal or convert them.
Beyond that, the notes do not by themselves show that the attacker has responded, accepted any proposal, or intends to move the funds in a particular way. For now, the next verifiable development would be any on-chain movement from the identified wallet or additional researcher findings linking other addresses to the same theft.
Source: www.coindesk.com