pull down to refresh
reply
reply
Yes, instead of runner ng their own instance of core and querying the block data, they relied on a third party block explorer to figure out which addresses to attack.
This means the block explorer company likely has logs of the queries, possibly IP addresses or browser finger printing data.
reply
Well... it's now time for pitchforks & shiz and everyone is going to be busy with that.
But what may be interesting is to find out which explorer was used for the initial theft itself, which can be open source investigation. May help in access log retention.