pull down to refresh

Stupid, basic question: how do we/they know which tx are from coldcards...?

There a specific marker in some transactions of the thief?

I think the attacker is just grinding out low entropy deterministic seeds from the bad RNG but and then scanning to see if there are any funds there.

Potentially when someone spends to the mempool it might flag a UTXO as being a target to look at too. Idk all the technical specifics tho

reply
I think the attacker is just grinding out low entropy deterministic seeds from the bad RNG but and then scanning to see if there are any funds there

Yes, that much I gather. How do we know which transactions are that? (Such that we can arrive at the number 1131 BTC or whatever and show them publicly?)

reply

where funds were swept to. Number is a minimum floor estimate. Likely more

https://coldcard-watch.vercel.app/methodology.html

reply

Aha, so basically attacker "revealed" himself by consolidating...?

reply

yea, I think there’s a ton of individual attackers now tho too since anyone with compute can do it

reply

Here is from the methodology section of the website.

If anything, I think they may be undercounting.

reply