pull down to refresh

I think Praveen is on the right track there. The attacker probably used some block explorer API and didn’t think that any address would have so many UTXOs.

Also, it would have been way harder for people to identify this as an attack if the attacker had used a different recipient address for each sweep.