Over 1,359 BTC stolen from Coldcard wallets remain mostly untouched, even as the hacker was publicly offered a laundering deal on the Bitcoin blockchain. On August 1, a transaction sent to one of the thief's addresses included a clear message advertising services to "clean" the stolen funds in exchange for 10% of the total, along with a Telegram contact.

This brazen onchain solicitation used OP_RETURN, a Bitcoin feature that embeds permanent text in transactions. Instead of transferring coins, the attacker was targeted directly with what appeared to be a laundering pitch. Some speculate this could be a trap set by law enforcement or a rival, while others wonder if it’s a genuine proposal.

Firmware Flaws and Wallet Bricking Cast Cloud Over Coldcard Users

The stolen coins arrived after a new wave of attacks exploited an old firmware vulnerability that allowed attackers to reconstruct weak wallet seeds. The flaw has been linked to multiple thefts since July 30. Meanwhile, users have reported emergency firmware updates have bricked some Coldcard hardware wallets, leaving them unusable.

According to Coldcard Sweep Watch data, most of the stolen bitcoin has been swept into a handful of addresses controlled by the hacker, making the theft unusually transparent on Bitcoin's public ledger. The case raises questions about how the stolen funds will be moved or laundered while the community watches closely.

This content is for informational purposes and does not constitute financial advice.