pull down to refresh
Looks like it was the CTOs commit. That's not to say that he didn't pull changes from elsewhere. I'm leaning more and more toward the "Retirement Attack" the more that comes out. Honestly the lawsuit is gonna be lit. We're probably gonna learn a lot.
I'm looking forward to the Adam Mckay movie about this either way
That seems more plausible to me but I don’t have a strong feeling about how plausible it is.
Another possibility is that it was initially a genuine mistake that someone later saw the opportunity to exploit.
Given how many people quickly identified it once the symptom drew eyeballs leads me towards the latter, if someone did know about it for a long time they were playing chicken with other potential attackers.
AI could have caught them off guard?
Lots of people are saying that this would be very easy to miss in review, so it seems plausible that someone who became aware of it would also come to that conclusion.
Possible, but let's assume they knew about it before AI could identify it without too much hand-holding... 6-12 months or so ago give or take?
That means they had time to generate keys in the entropy space and check addr indexes to get an idea of how much they could steal... which has been far more than anyone other than a nation state can reasonably wash.
If it was an inside job, thats 5 years of betting no one notices.
It seems like all the rationale would point to doing this some time ago if it wasn't recently discovered, and that makes the AI ad-hoc discovery by a random in the last few weeks or months the most plausible imo.
Still pretty sophisticated to bury it so, being able to pull that off and not know how damned near impossible it will be to cash out seems unlikely... but if it was an off-shore wagie maybe they're content to drip small amounts and aren't bearing the cost of the legal/business destruction.