> flagged as stolen
That would imply some sort of centralized authority to decide exactly what 'stolen' means. Even if a third-party service kept track, it'd be meaningless in short order, as mixers exist...
When the client sends the address the change is returned to a new change address, and the wallets are being designed now to never reuse addresses.
So it would become very hard to determine which of the outputs are change addresses and in the same wallet.
Blockchain.info has tagged it as inputs.io hack. And a couple users have tagged it as well with public messages. But besides that, as far as I know, all anyone can do is watch it get drained.
[1] https://bitcointalk.org/index.php?topic=248803.msg3509247#ms...
In other words, each time a coin changes addresses there is a plausible deniability for the owner of the receiving address that s/he received the coin as a result of a legitimate transaction (sale of goods/services, donation, whatever)