Found something interesting while looking at new txs made to an address containing hacked coldcard funds.
Funds were sent from an Ocean miner payout address to an address linked to hacked coldcard funds and then that UTXO was peeled off immediately.
Could this dummy have accidentally sent his mining pool payout to the address containing hacked funds? Copy pasta mistake?
Block whose coinbase paid miner (tag OCEAN.XYZ):
Miner payout address (payout sat here ~14h 40m before moving):
Tx sending that payout to address containing stolen funds:
Stolen funds address (current balance ~0.69 BTC of stolen bitcoin):
Tx moving funds that originated from Ocean out of the address containing hacked funds:


The Mempool Open Source Project®
Explore the full Bitcoin ecosystem with The Mempool Open Source Project®. See the real-time status of your transactions, get network info, and more.

The Mempool Open Source Project®
Explore the full Bitcoin ecosystem with The Mempool Open Source Project®. See the real-time status of your transactions, get network info, and more.

The Mempool Open Source Project®
Explore the full Bitcoin ecosystem with The Mempool Open Source Project®. See the real-time status of your transactions, get network info, and more.

The Mempool Open Source Project®
Explore the full Bitcoin ecosystem with The Mempool Open Source Project®. See the real-time status of your transactions, get network info, and more.

The Mempool Open Source Project®
Explore the full Bitcoin ecosystem with The Mempool Open Source Project®. See the real-time status of your transactions, get network info, and more.

