If there were truly “selective sweeps,” then those cases also don’t map cleanly to the Mk3 flaw. The randomness bug doesn’t give an attacker partial access. it gives them the full seed. Once the seed is weak, every UTXO derived from it is equally exposed. Selective movement means something else was different between those UTXOs: a separate backup path, a reused seed, a partially‑exposed key, or an external leak. The Mk3 flaw is deterministic. Selective behavior isn’t.

Replies (1)

I don’t know…. I was pretty careful with never reusing addresses and keeping the device completely airgapped. Could it be possible that they got my key because this mk3 was a 1 of 3 in a multi sig setup and the utxo that got drained was change from a utxo that was recently moved from the multi sig vault? Their script didn’t pick up the unrelated utxos that were still left in the wallet? Honestly fuck hackers. The fact we have to worry about this shit and protect ourselves against pieces of shit that steal for a living is an indictment on humanity