pull down to refresh

Well, also that it seems to be more than one person?

source

168 sats \ 8 replies \ @k00b 30 Jul

If it's a compromised Sparrow there would be more than one victim.

reply

which version of sparrow?

reply
301 sats \ 0 replies \ @k00b 30 Jul

There were fake sparrows on the app store not too long ago.

reply

ah yes, i see that.

Also, it seems like they didn't even take all the utxos at a single address:

source

reply

I think Praveen is on the right track there. The attacker probably used some block explorer API and didn’t think that any address would have so many UTXOs.

Also, it would have been way harder for people to identify this as an attack if the attacker had used a different recipient address for each sweep.

reply
201 sats \ 3 replies \ @k00b 30 Jul

It could also still be an RNG problem ... if the reports of partial sweeps are wrong or the thief doesn't feel comfortable stealing everything in an individual's wallet (which would be surprising) or, after your edit, taking only some utxos is a bug in the attack.

reply
241 sats \ 1 reply \ @Scoresby 30 Jul

reply

Beat me to it.

reply

from lopp:

I had someone contact me about this earlier today and the one thing they noted is that their full wallet balance was not swept; it was only a handful of UTXOs that were swept. I told them I suspected that their seed was not compromised, but rather something they did had compromised individual private keys.
reply

Over 1300 UTXOs were spent toward the alleged attacker’s address, and we have had multiple different reports, so it’s likely that this affects a larger number of people.

reply
346 sats \ 1 reply \ @Scoresby 30 Jul

Yes, looks like narceilo identified some more:

source

reply

That one seems to preceed the other one

reply
124 sats \ 0 replies \ @nout 30 Jul

The attacker may be just batching the load here. It's reasonable to assume that more draining is to come.

reply