๐Ÿšจ THE #COLDCARD ATTACK HAS ESCALATED ๐Ÿšจ MOVING YOUR FUNDS ACTUALLY MAKES YOU A HIGHER PRIORITY FOR GETTING SWEPT. ๐Ÿซช The attackers are clearly running a script that will IMMEDIATELY sweep you if you try to move your funds. ๐Ÿซ  It appears that they have been compiling a database of affected addresses for YEARS, so if an affected address transaction hits the public mempool, the attacker is doing an INSTANT RBF (Replace By Fee) to beat out the person trying to save their funds. ๐Ÿ˜ญ The ONLY way to avoid this is to hand your transaction DIRECTLY to a miner THAT DOES NOT BROADCAST TRANSACTIONS so that it will not hit the public mempool. ๐Ÿ’โ€โ™‚๏ธ This is SO fucked; spread for awareness. ๐Ÿค™

Replies (5)

Would this apply if moving from multi sig where just 1 of 2 is CC generated keys?
I approve of non-broadcasting methods for recovery, but we still have to wonder what kinda surveillance & #KYC mechanisms exist in the narrow recovery window/method for people to retain their #Bitcoin / #BTC stash. ๐Ÿซช I'm sure 3 letters will LOVE that data trove. ๐Ÿซ  It's bad ALL THE WAY DOWN. ๐Ÿค™
Monero Dog's avatar
Monero Dog 1 week ago
See my pinned post for how to mitigate this.
Default avatar
H 1 week ago
Why would attackers wait the address to transact instead of directly stealing utxos?
The attack began as 6-7 figure sweeps, then moved down to 5-6 figure sweeps; my assumption is they are prioritizing big bags first for max extraction. ๐Ÿคทโ€โ™‚๏ธ If you order the attack solely by whale โ†’ shrimp UTXOs, then all the small fries have time to scurry while you're spending compute time taking down the whales; unless you have a radar out to stop them from escaping. ๐Ÿ’โ€โ™‚๏ธ It seems there is a mechanism to impede ongoing flights to safety. ๐Ÿคฆโ€โ™‚๏ธ Snipe scurrying shrimp โ†’ back to the dormant whales. ๐Ÿซ  That seems to be the execution logic. ๐Ÿค™
โ†‘