pull down to refresh

During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.

We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.

We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.

https://nitter.net/clay_garrett/status/2083247006139503065

reply

They accept payment via credit card and via Bitcoin on-chain (no Lightning).

reply

The terrible 200

reply