pull down to refresh
reply
Yes, instead of runner ng their own instance of core and querying the block data, they relied on a third party block explorer to figure out which addresses to attack.
This means the block explorer company likely has logs of the queries, possibly IP addresses or browser finger printing data.
reply
Source