Coldcard hack linked to 1,359 BTC draws onchain laundering pitch as stolen coins stay idle

A message embedded in the Bitcoin blockchain offered the thief laundering services for a 10% fee after the Coldcard hardware wallet hack, highlighting rare direct outreach to a suspected attacker.

BTC

Summary

A major Coldcard hardware wallet hack involving more than 1,359 BTC was followed by an unusual onchain solicitation offering laundering services to the thief for a 10% fee. The message was embedded in the Bitcoin blockchain, underscoring a rare instance of someone publicly trying to reach a suspected attacker through transaction data. Earlier monitoring had identified the attacker’s largest consolidation address as holding 562 BTC and receiving a dust transaction carrying an OP_RETURN message with the laundering pitch. That transaction sent 1,590 sats to the attacker address, while the sender spent 0.002347 BTC in total and routed the remainder back as change, putting the advertising cost at about $1.3. The message also included a Telegram account, though it was not disclosed publicly, and there is no evidence the contact is genuine or that the attacker accepted any offer. The stolen Bitcoin had not moved in the earlier monitoring, and the episode by itself does not show that any laundering activity has begun.

Terms & Concepts
  • OP_RETURN: A field in a Bitcoin transaction that allows small pieces of data or messages to be written to the blockchain.
  • dust transaction: A very small-value transaction, sometimes used to deliver a message or interact with an address onchain.
  • onchain: Recorded directly on a blockchain, making the activity publicly visible in transaction data.