pull down to refresh
reply
reply
which version of sparrow?
reply
There were fake sparrows on the app store not too long ago.
reply
reply
I think Praveen is on the right track there. The attacker probably used some block explorer API and didn’t think that any address would have so many UTXOs.
Also, it would have been way harder for people to identify this as an attack if the attacker had used a different recipient address for each sweep.
reply
reply
I had someone contact me about this earlier today and the one thing they noted is that their full wallet balance was not swept; it was only a handful of UTXOs that were swept. I told them I suspected that their seed was not compromised, but rather something they did had compromised individual private keys.
reply
reply
that still doesn't explain why only some of the private keys are being compromised.
if it's an RNG weakness, then isn't an attacker still just "searching" for coins, and as the UTXOs turn up, racing against other attackers to claim them?
so there is also a secondary "game", of building transactions that are likely to get mined ASAP, rather than just huge dust sweeps that end up mostly rewarding miners.
What's weird, from reading X threads, is that only some UTXOs from wallets are being swept like only some of the private keys were compromised. If those are child keys this wouldn't be an RNG issue. They claim they were trying to use Sparrow as a watch only wallet but "SD card imports the wallet into Sparrow." So maybe he had a compromised Sparrow and the SD card was a backup. But that still doesn't explain why only some of the private keys are being compromised.