Security

Coldcard hacker’s wallet becomes a graffiti wall of pleas and hustles as losses mount

3 min read
Coldcard hacker's wallet becomes a graffiti wall of pleas and hustles as losses mount

A bitcoin wallet tied to the Coldcard exploit now holds roughly $36 million in stolen funds. It has also become a public message board. People are paying transaction fees to write on-chain notes to the thief.

Blockchain researchers, including Galaxy Research, flagged the address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r as one of the attacker-controlled wallets receiving transfers since the theft began July 30, according to CoinDesk.

The Coldcard hardware wallet exploit, first detected that day, has produced confirmed losses topping $100 million, CoinDesk reported. Decrypt put the figure higher, at roughly $130 million in a related piece. Figures differ. Neither outlet disclosed its counting method.

The messages arrive via OP_RETURN, a Bitcoin feature that lets any transaction carry a small permanent text string. The graffiti costs only a transaction fee. It lasts as long as the chain does. Senders cannot delete or edit what they write.

Some notes beg. “You stole, please return some,” one read. Another, flagged by Arkham Intelligence, paired “Please Please Please” with a return address. A third asked for 80% of one victim’s 5 BTC back.

Others are hustles. One pitch offered to launder bitcoin for a 10% cut and listed a Telegram handle. Another asked for “1 BTC for my Bitcoin journey.” A few read like poetry: “Monday owns my day / five plus ten bitcoin stranger / let me call in free.”

CoinDesk noted the senders’ motives are difficult to verify. Genuine victims and opportunists sit side by side in the same ledger.

This has happened before. In the 2020 LuBian mining pool theft, more than 127,000 BTC vanished. The pool’s operators used OP_RETURN to try negotiating directly with the attacker.

The root cause is drawing industry attention. Coldcard maker Coinkite disclosed a flaw traced to a March 2021 firmware build, according to Decrypt. The bug triggered a software fallback that bypassed the device’s hardware random number generator when generating recovery seeds. Some private keys became guessable.

Coinkite released patched firmware on Sunday and told affected users to move funds to newly generated wallets. The firm did not respond to Decrypt’s request for comment.

Ledger, which makes competing hardware wallets, said its devices were unaffected. They generate seeds differently, drawing the full 256 bits of entropy from a certified Secure Element with no software fallback. “We’re treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness,” Charles Guillemet, Ledger’s CTO, told Decrypt.

Guillemet framed the incident as a failure of review, not just code. “Open source and reviewed are not the same thing. This flaw sat in public code for more than five years until, reportedly, an adversary used AI to find it, a reminder that being open and being reviewed are two different things,” he said. The AI claim is unconfirmed. Decrypt attributed it to Guillemet without independent verification.

He argued the fix is hardware and certification. “Randomness has to come from physics, not a formula. It has to be certified by people whose job is trying to break that claim, not just asserted by the vendor,” Guillemet said. Coinkite has not said whether future Coldcard builds will adopt a certified entropy source.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.