๐จ THE #COLDCARD ATTACK HAS ESCALATED ๐จ
MOVING YOUR FUNDS ACTUALLY MAKES YOU A HIGHER PRIORITY FOR GETTING SWEPT. ๐ซช
The attackers are clearly running a script that will IMMEDIATELY sweep you if you try to move your funds. ๐ซ
It appears that they have been compiling a database of affected addresses for YEARS, so if an affected address transaction hits the public mempool, the attacker is doing an INSTANT RBF (Replace By Fee) to beat out the person trying to save their funds. ๐ญ
The ONLY way to avoid this is to hand your transaction DIRECTLY to a miner THAT DOES NOT BROADCAST TRANSACTIONS so that it will not hit the public mempool. ๐โโ๏ธ
This is SO fucked; spread for awareness. ๐ค
Login to reply
Replies (5)
Would this apply if moving from multi sig where just 1 of 2 is CC generated keys?
I approve of non-broadcasting methods for recovery, but we still have to wonder what kinda surveillance & #KYC mechanisms exist in the narrow recovery window/method for people to retain their #Bitcoin / #BTC stash. ๐ซช
I'm sure 3 letters will LOVE that data trove. ๐ซ
It's bad ALL THE WAY DOWN. ๐ค
See my pinned post for how to mitigate this.
Why would attackers wait the address to transact instead of directly stealing utxos?
The attack began as 6-7 figure sweeps, then moved down to 5-6 figure sweeps; my assumption is they are prioritizing big bags first for max extraction. ๐คทโโ๏ธ
If you order the attack solely by whale โ shrimp UTXOs, then all the small fries have time to scurry while you're spending compute time taking down the whales; unless you have a radar out to stop them from escaping. ๐โโ๏ธ
It seems there is a mechanism to impede ongoing flights to safety. ๐คฆโโ๏ธ
Snipe scurrying shrimp โ back to the dormant whales. ๐ซ
That seems to be the execution logic. ๐ค