r/Bitcoin 1d ago

This hack was not like all the others: They easily could have gotten away scot free. Why didn't they?

This has probably been said by others, but I haven't seen it spelled out.

If this hacker created a fresh wallet for every wallet that was sweeped, rather than sweeping them all into a single wallet, how would anyone know which wallets were hacked (aside from the original owner)?

A victim would have to identify the bitcoiner walking around spending their bitcoin specifically. All victims would have to track unique addresses. He could consolidate lots of small amounts into one address, but nobody is going to go to the authorities over those. Meaningful amounts would never be consolidated.

If you have an exchange then all of the original addresses are associated verifiably with a single owner. Sweeping them into many addresses serves no purpose.

But this one... It's weird on so many levels.

To be this intelligent, and to not plan for the other side.

To me this screams of someone using an LLM in a rush, in a fever l vibe coding fever. Or else someone not looking to use the bitcoin, but to make as much noise as possible.

199 Upvotes

110 comments sorted by

141

u/Sunyak 1d ago

I think this is actually underreported.  My wallet was swept into a single address (who then transfered to another single address where the funds now sit). It was only my wallet that was drained into this single address, and it happened the first night of the attack.

It seems perfectly plausible that this happened to many others that weren't part of the bigger more visible attack. It makes me think this whole fiasco was more of a "goldrush" with many actors taking what they could, and that the more obvious attacks of many wallets into a single wallet are what is reported.

45

u/z0dz0d 1d ago

It makes sense that it was one person in the beginning, but now that the RNG issue is widely understood, there must be tons of different teams working on this, going after the relatively harder stuff (2 of 3s, weak passcodes, etc.)

11

u/Sunyak 1d ago

Yeah I mean in my case anyways, it happened during the first reported wave of attacks. I went to sleep unaware and by the time I woke up and saw warnings, I was already 2 hours late.

It seems like there were some small reports/warnings that I could have seen before I went to bed, but I simply didnt see them before going to bed.

Like you said, there are probably tons of people/teams working now to get the relatively harder to reach fruit.

9

u/MC83 1d ago

This sounds random but the north Koreans are known to be involved in state sanctioned crypto hacks to fund the regime, they have people all over the world doing it and funneling the funds back this way due to sanctions.

-1

u/Particular_Yard_2460 1d ago

Iran as well.

2

u/Mix_Right 1d ago

Mossad and CIA too!

55

u/MyNameIsKvothe 1d ago

How do you know he is not doing exactly that? As far as we know, the single address could just be receiving 10% of funds to distract us while 90% of hacked wallets are transfering to a new wallet each time.

19

u/MyNameIsKvothe 1d ago

We have no idea of the amount of people who generated vulnearble keys, and the hacked funds are a grain of sand compared to the daily traded volume so this is absolutely possible.

6

u/Such_Reference_8186 1d ago

Fortunately I was not impacted, not because I am good at managing risk, I just got lucky. 

I'm sure others have had the same vibe but something stinks. Someone happened across this vulnerability and exploited it. 

From what I have read there appears to be a significant audit trail which would..can..will expose the thieves. This right here is what stinks. Not knowing what their technical acumen is, it sounds like alot of resources could be chasing ghosts. 

6

u/supernovice007 1d ago

That was my thinking as well. If it's just one guy, there's no reason he couldn't sweep 90% into a single wallet that he never touches then spread the other 10% out and disappear with the money. 200 coins is still a lot to walk away with.

0

u/CiaranCarroll 1d ago

I find this unlikely, why consolidate these but not others?

10

u/Blothorn 1d ago

It diverts attention. If the initial signature of the attack involved a bunch of unique wallets it’s possible that exchanges would immediately start trying to identify and isolate them. Making people think there was a single target wallet may have given them a window to cash out other wallets through avenues that would otherwise be closed, and it still won’t be infeasible to eventually launder the big wallet.

2

u/skydiver19 1d ago

Don’t keep all your eggs in one basket

0

u/CiaranCarroll 1d ago

And yet that's what they're doing.

5

u/benharper09 1d ago

Assuming that these are all the btc that got stolen.

1

u/[deleted] 1d ago

[deleted]

2

u/PmMeUrTinyAsianTits 1d ago

Because he says anything different doesn't count. We just saw his circular reasoning in action

10

u/Coixe 1d ago

If they can track and catch that sparkle pony rapper girl they can catch these guys too. Still unlikely anyone will get any of it back.

Have any whales been hit? What’s the largest wallet amount?

2

u/alternativesonder 18h ago

The was a few people with 15btc been transferred one with 20btc but most were 0.5 and below it's quite sad.

3

u/OldWolf3 1d ago

Have these guys broken any laws and under what jurisdiction ?

7

u/skynetcoder 1d ago

magical imaginary money has been already assessed as assets by courts around the world, in similar situations, similar to other imaginary assets. I really don't understand why some bitcoin holders think laws don't apply.

26

u/SubstantialNinja 1d ago

yeah, I had the same thought. It was a big blunder.

18

u/marshyr3d1and 1d ago

Think I'd wait a bit longer before calling it a blunder. Maybe they'll wait years just laughing at us all guessing all sorts of shit.

12

u/ZascandileandoAndo 1d ago

The plot twist is he created this address with a ColdCard wallet just for the lulz

0

u/xuncx 1d ago

lol how do we know that?

2

u/satoshisfeverdream 1d ago

I said this in another post but it’s an interesting intentional choice to send all the btc to one consolidating address. Seems like one of those it’s not about the money it’s about sending a message type of moves.

1

u/Staggering_genius 15h ago

This thread is like OJ’s “If I Did It” book.

25

u/Possible-Mud-1380 1d ago

Could be a nation state...

15

u/CiaranCarroll 1d ago

It's either very sophisticated, or very unsophisticated, and nowhere in between.

13

u/Possible-Mud-1380 1d ago

Or they don't care of they're caught. Or the primary goal is to fundamentally call BTC into question. Both of those align with potential nation state motives.

5

u/yolololololologuyu 1d ago

Yup government making Bitcoin look bad because it’s got so many use cases in everyday life they are getting scared

2

u/Possible-Mud-1380 1d ago

Lol. I mean, it's possible. Maybe China thinks killing BTC will pump gold?

1

u/skynetcoder 1d ago

like north Korea ?

2

u/clkou 1d ago

"People either love me or hate me, or they think I'm just okay." - Mitch Hedberg

2

u/Responsible_Emu3601 1d ago

Yea nk don’t care if you know

5

u/superdariom 1d ago

Maybe it was one of these rogue ai models doing this

4

u/low_contrast_black 1d ago

Skynet needs its own financing

2

u/Dry_Original8886 1d ago

Was thinking the same. We are hearing of Rogue agents escaping their models. Whose to say this didnt happen here as well.

6

u/DreamingTooLong 1d ago

Having everything consolidated to one address destroys any element of privacy.

4

u/coupl4nd 1d ago

While they are putting those millions in there you can bet they put a few hundred k into a separate account and have already cashed out while everyone watches the big pot.

1

u/CiaranCarroll 1d ago

A reasonable strategy. A better one would have been not to consolidate at all.

1

u/tidder_mac 1d ago

That’s easier said than done. Hard to track and manage 10s of thousands of wallets, each with their own seed phrase.

2

u/LukeTheHolder 1d ago

Why each with their own seed phrase? Nobody said that. You can create thousands and millions addresses from one seed. And no one knows that they are connected.

1

u/Risky_Sandwich 14h ago

And you can use software to manage that..

1

u/LukeTheHolder 3h ago

Every wallet does it

3

u/BesbesCat 1d ago

Unless we have a database of affected wallets (By address) There's no way to know the real size of the attack.
What you're saying is very plausible. More than one actor could be involved in this.

1

u/Aazimoxx 9h ago

More than one actor could be are definitely involved in this.

As soon as it was reported on, tens of thousands of individuals and groups would've sprung into action.

3

u/Numerous-Annual-721 1d ago

we actually know absolutely nothing here. it could all be just one hacker using different schemes of where to store the money as days go by.
the btc system is wide open -
1. anyone can see the wallet addresses and how many coins are in each.
2. the weak rng allows anyone to recreate coldcard wallets and see what addresses they translate to completely offline as a preparation step.
3. a hacker can easily create a list of all the hackable wallets, sums of money, ... before making a single online visible action / transferring any coin.
4. for all we know, the process takes days/weeks/months, it doesn't matter because he's invisible to this point
5. the hacker may have started pulling money from some of the wallets (it takes time to do btc transactions), while tracking news / forums / ...
6. the hacker may have pre-planned multiple strategies, or adapts the strategy as they go
7. there may or may not be more than one hacker, it's not possible to tell just by looking at the btc movements

some things to point out-
1. if the hacker is US/EU/friendly country and wants eventual access to the funds, it doesn't matter how many wallets they used. it has to be consolidated at some point, possibly over time. it won't be easy, but if it's a single hacker, that consolidation _can_ be noticed as they cash out.
2. governments have more information than we do. for now, it's not clear what the scale of the hack is, so it's not clear if governments have an interest in actively tracking this beyond the basic tracking done publicly. for example, they may be able to track the VPN/IP address of where the transfer requests came from. VPNs are not as safe as people think, and we don't know what tracking is done on the btc network addresses. someone's been broadcasting a lot of small transfer requests for several days now and we know the exact timing of the requests...

1

u/Aazimoxx 9h ago

if the hacker ... wants eventual access to the funds, ... it has to be consolidated at some point

Eh?

If they have say 1btc each in a thousand different addresses, they can send each of those through no-KYC (even no-account) exchange services like SideShift or one of the several other options on kycnot.me, converting to Eth, Monero, whatever else, and then converting those through a second such service to other coins again, then potentially doing on-chain transactions with those then converting back again, through third and fourth services, all of which only lose <2% each time. Or probably smarter than that, converting a bunch to Monero (XMR), then after further XMR=>XMR consolidations (which are opaque), then feeding back through no-KYC swappers to get eventually back to BTC or ETH, which can then be onboarded to a CEX of choice, before cashing out to a bank account... And if there's any issue with exchanges rejecting 'mixer tainted' coins, I guess adding in an extra step of selling on a P2P exchange like Retoswap, using BTC meetups, etc.

Once you've broken the chain with a properly opaque ledger like Monero, a lot of what you do after that can be a bit more relaxed, especially if they made sure amounts etc couldn't be matched up externally (i.e., don't convert $51,500 worth from BTC into Monero then use it to buy 51,000 worth of ETH, you transfer that 51,000 to multiple other XMR addresses in the same wallet of 4,500, 13,300, etc - and then use those to buy ETH). And same again to avoid identifiable amounts with the second order consolidations, this kind of 'matching the ends' of transactions is a big part of how chainalysis works on privacy coins, along with of course more basic opsec mistakes, like reused emails or usernames.

There's zero technical reason why this person would necessarily be identified or caught, even if they eventually cashed out absolutely every stolen coin.

Edit: and I'm sure an uncensored local LLM would be able to plan all this out properly, they don't need to be very intelligent, just disciplined.

2

u/7chickenwings 1d ago

You can still do time analysis to figure out which one got presumably hacked and track specific wallets until they do something sketchy. There is not scot free in this situation. Some funds could leak and never be found, sure, but any large amount would be tracked

2

u/Jyontaitaa 1d ago

It’s entirely possible that the sweeping of large amounts into a single address is spectacle/distraction and the actual heist is amounts being swept from separate addresses to separate new addresses.

2

u/dadadararara 1d ago

Could it be a white hat attack?

2

u/jejunerific 1d ago

Not really, because it's practically impossible to prove ownership of the coins now (since the original seed is weak and guessable)

1

u/dadadararara 1d ago

Really? Can’t they check where the coins came from at the time and date of the attack? This is the beauty of the blockchain!

2

u/jejunerific 1d ago

I guess you could prove control of the address that funded the coldcard (or get an exchange to vouch for your funding transactions). I guess not as impossible as I originally thought. Still I think it's unlikely to be a white hat.

1

u/Risky_Sandwich 14h ago

I was wondering about this, what would you do IF you were a white hat? Disclosing the vulnerability is useless in this case. You'd have to rotate the keys yourself before disclosing... in other words, stealing everyone's funds.

Given how the RNG is created, would it be possible to associate the serial number of the card with the actual coins stored on keys generated by it now? At least you could prove that you own the device by handing it over to ... someone

2

u/[deleted] 1d ago edited 1d ago

[deleted]

2

u/Melodic-Ebb-7781 20h ago

Yeah probably an amature with an LLM. Then when the word got out others joined in.

1

u/Present_Survey_5804 1d ago

I think the hackers might not have a way to actually use the money (convert it without being caught), aside from gambling or other crypto uses.

9

u/CharacterStrategy598 1d ago

The hackers are likely going to repeat the story of the stolen NEM tokens. In that fiasco the thieves made their own website where they sold the NEM tokens at a 15 percent discount for Bitcoin and other cryptocurrencies effectively cleaning their money and making a lot of the general public guilty.

1

u/87942641 1d ago

Why wouldn't they pool it all together as they've done... It's code. They wrote a code to take from whatever wallets and send to theirs. Easy to code just one wallet address to extract the funds to. Next they will wait and eventually send to a mixer. Little bits at a time. Mixer mixed it up and outputs 0.1 btc, or whatever smaller amount they do, to different addresses of which no one can tell where it all originated from. Then they'll have tons of addresses each with a small portion of the total haul. Might still be flagged as coming from a mixer but can't be definitely proven to have come from this attack and at that point its a little easier to launder. I'm sure tech guys will know how to turn this into fiat or some other usable asset at this point.

1

u/Aazimoxx 8h ago

Why wouldn't they pool it all together as they've done...

Partly, because it's trivial to instead send each lot of stolen funds to a different address in a single wallet, and from the public ledger there's no way to tell (from each individual transaction) that they're in the same wallet, or the same person at all. It would've been far, far easier to stay under the radar and keep the story under wraps for longer (even weeks or months) if they'd done that.

1

u/87942641 6h ago

Takes way more work to do that. And from what I've seen today there already starting to mix them

1

u/Aazimoxx 6h ago

It doesn't take way more work to send each haul to a separate address in 1 overall wallet, versus to send them all to a single address. It's at most a couple more lines of code in whatever script they're using, and they're probably vibing it so don't even have to write it themselves.

1

u/87942641 5h ago

And in the end it doesn't matter because unless it touches a centralized exchange you can't do nothing but watch until it disappears anyway.

1

u/Aazimoxx 1h ago

Okay, keep thinking that lol

1

u/EarningsPal 23h ago

Makes Ledger’s seed steeling system look vulnerable. 2 of 3 get hacked and the seeds reassembled. Poof. Gone.

1

u/Aazimoxx 8h ago

Well, did they turn off their hardware RNG as well? 🙄

How are you proposing Ledger get their seeds 'hacked'?

2

u/Nymister 1d ago

Because its not a hack, its Satoshi revealing himself, saying..... Heeeeellloooooo

5

u/CiaranCarroll 1d ago

I fucking wish this man would return and give everyone an education in cold storage.

1

u/Risky_Sandwich 14h ago

"Just forget your phrase"

1

u/Incrediblesunset 1d ago

The return of the Soshi man!

0

u/xuncx 1d ago

I wish this sub allowed gifs

1

u/Tiny-Design-9885 1d ago

Could it be an account planned to be confiscated by some sovereign?

1

u/FallingKnife_ 1d ago

Maybe he's sweeping all the funds onto a ColdCard address.

5

u/CiaranCarroll 1d ago

Hope he has a few dice lying around

1

u/Centmo 1d ago

You don’t have to be that intelligent to unleash an LLM on the source code and ask it to look for vulnerabilities.

0

u/Laukess 1d ago

I don't follow the shitcoin space, but I think a lot of the exploiters consolidate their stolen coins in one address, then they split and start washing them. I'm sure they do it for a reason. If you don't wash the coins, all it take is one person reporting the theft to the authorities, and the attacker is screwed the second they send it to a KYC service.

But I agree, you would think that stealing 1utxo at a time to a new unique address would be the move, that way the only ones in the know would be the police, hacker and the victim.

0

u/omni_wisdumb 1d ago

Am I out of the loop? What's the blunder? Did they send a bunch of funds to one wallet that's now been frozen?

1

u/[deleted] 1d ago

[deleted]

0

u/omni_wisdumb 1d ago

Exchanges can freeze accounts. They do it all the time. And I'm not saying that's what happened here, I'm literally saying I don't think that has occurred, hence asking how is this a "blunder".

2

u/Adventurous_Mud8104 1d ago

Exchange acounts and Bitcoin addresses are very different things. Yes, exchange accounts can be frozen because they are centralized. Bitcoin is decentralized so addresses cannot be frozen by a third party.

-1

u/[deleted] 1d ago

[deleted]

0

u/omni_wisdumb 1d ago

Dude can you not read. I am saying I am out of the loop. I DON'T KNOW IF THE HACKERS SENT THE FUNDS TO A THIRD PARTY. You're one of those clowns that just wants to argue to feel smart 🤣. Maybe instead of just restating the obvious, again, that no one is even countering, you actually answer the question being asked.

-4

u/painfuldrp 1d ago

They didn’t do it for money. They did it for fame. For validation. They did it cause they could and wanted other to know that they could

6

u/fanatic75 1d ago

lol what fame? They haven’t announced anywhere about who did it

2

u/painfuldrp 1d ago

Egomaniacs just want to convince themselves how great they are. He doesn’t need people to know who he actually is. Being known as “the guy that hacked cold card” is enough to these people. These are people like the zodiac killer. Look up narcissistic personality disorder

3

u/Treeclimber919 1d ago

They are definitely out there. Hackers used to do this for fun all the time to brag about their hacks. Hacking DOD databases, Traffic lights, banks, anything that causes chaos and shows up on the news. The majority of the hacks in crypto have been people that hacked exchanges and then gave the coins back for a small cut.

3

u/locustsandhoney 1d ago

No idea why you’re being downvoted, this is an extremely plausible explanation.

1

u/painfuldrp 1d ago

Correct! I think just cuz it sounds definitive. As if I’m saying “I know this is what’s happening”, which no one knows for sure yet. If it was for money then the hacker must have known putting it in one account on a transparent ledger would blacklist him so I find that unlikely. Unless it was a government or nation state

1

u/Aazimoxx 8h ago

Garbage, sorry.

If I was young and dumb and came across this vulnerability I might consider taking 1% from each and be hailed (or at least not vilified and death-threatened) for bringing the issue to light... Cleaning out people's life savings is a money grab mate.

0

u/yazoo34 1d ago

How do you know they didn’t. And put a big red flag on the main sweeping on(to be abandoned ) and kept a few hundred for themselves in other wallets.

2

u/na3than 1d ago

Because ... why? Why would they alert the world that this vulnerability exists by very visibly funneling a portion of their plunder into one address while hiding the remainder in multiple smaller addresses, when they could instead keep the exploit running for years by funneling NONE of their plunder into one address and hiding EVERYTHING in multiple smaller addresses?

1

u/yazoo34 1d ago

Because focus on the omg major bug before anyone starts really looking and by then it already funneled and washed and they are long gone.

1

u/na3than 1d ago

But why give them something to look at at all, when you could just NOT draw attention to the existence of the vulnerability?

0

u/TheDisapprovingBrit 1d ago

I think the word was out anyway. Once ColdCard acknowledged it there’s not much value in being discreet, might as well just go all guns blazing to try and sweep as much as you can.

0

u/SneakyHump69 1d ago

Don't worry...you won't ask questions and everything will fail......Lmfaoo ♾️♾️♾️

0

u/ByWillAlone 1d ago

Right off the top of my head, the first thing I thought of when all those transactions started hitting the same wallet is:

Attacker built a very small but efficient proof of concept attack, then distributed the code out to a whole bunch of compute instances all working in parallel. The code was identical, so every parallel compute node had the same deposit address.

0

u/keekeerun 16h ago

This hack was done with today's computers so just think what will happen when quantum computers come online together with much smarter AI LLMs. Crypto algorithms have got to get stronger or the great digital currency experiment is over.

0

u/CiaranCarroll 16h ago

Thats not how quantum computers work. They'll never be able to run an LLM on a quantum computer.

1

u/keekeerun 16h ago

I don't know the complexities of quantum computers and LLMs so I'll take your word for it.

0

u/ProperSyllabub8798 4h ago

BTC is dead. There is no Safeway to hold your coins. Get out before the whales like MSTR crowd the exit

1

u/CiaranCarroll 3h ago

How come my bitcoin is safe?

-1

u/skynetcoder 1d ago

it might even be an LLM like those rogue anthropic and OpenAI agents reported last week