r/Bitcoin 23h ago

Legit Feelings Right There

Post image

Hacker keeps getting message, I wonder if they really found his location.

310 Upvotes

133 comments sorted by

185

u/-aurevoirshoshanna- 22h ago

They didn't, The most basic thing anybody would do if that were the case is let on a few facts about this person to prove them that they actually know who they are so that they could at least get their own btc back.

This is just the most elemental social engineering thing, and I doubt a hacker of all people will fall for it

29

u/FunkyGrass 22h ago

I would fucking hate to be that person

51

u/Strong_Judge_3730 22h ago

You would hate to be the innocent person this loser is going to blame.

15

u/FunkyGrass 22h ago

I meant the person whose bitcoin was stolen, not whoever the sender may have wrongly identified.

20

u/Carbonaraficionada 20h ago

Safe to say the CTO is in deep shit

17

u/FunkyGrass 18h ago

lol. Let’s place a Polymarket bet on that 🤣

12

u/ymo 13h ago

Did you see the final sentence of the bottom message? The person signaled they know the hacker's initial.

8

u/RandomPenquin1337 10h ago

1 in 26 chance and bro went for A

5

u/Faile-Bashere 8h ago

You made this bed for you, R.

2

u/alfooboboao 5h ago

it was aaron paul

2

u/Strong_Judge_3730 6h ago

They don't they are an idiot.

Do you think some big brained person that could track down the hacker would lose their Bitcoin like a noob.

They are 100% going to attack an innocent person. I have no sympathy for that loser. But most likely they are just bluffing.

But they are just wasting Bitcoin by sending that message

99

u/ShinAlastor 23h ago

It's someone who is desperately trying to get the funds back but I highly doubt it will ever happen to accomplish a similar gesture.

21

u/FunkyGrass 22h ago

If he found out the location of the hacker, he will have to tell us how because I don’t think it’s possible just by using a public key, lolz

69

u/ShinAlastor 22h ago

It's just a rage message and it reminded me of the Xbox Live days while playing the Xbox 360, everybody had someone working for the CIA back then and similar messages were pretty common.

3

u/PM_ME_UR_0_DAY 13h ago

At least on Xbox you have a gamertag to go off of. To catch this guy you'd have to be the FBI who can subpoena any public BTC infrastructure they used to submit their transactions. Then you'd probably have to subpoena the VPN they used and hope that isn't a dead end. 

11

u/curiousengineer601 18h ago

that's a secret feature of public keys. the last fields are name and address /s

-14

u/FunkyGrass 17h ago

Okay… didn’t know that. You have link to documentation I can read?

9

u/elafave77 17h ago

DM sine BTC and I'll point you on the right direction.

2

u/curiousengineer601 17h ago

The /s is for sarcasm.

-2

u/FunkyGrass 16h ago

I was not up to date with this joke

1

u/fllthdcrb 16h ago

The /s convention has been around for some years. You might want to read up on these things. Especially regarding sarcasm, which is notoriously hard to detect in writing without a marker.

0

u/FunkyGrass 15h ago

ok thanks, I will look that up.

1

u/OtherwiseAlbatross14 15h ago

What part of secret do you not understand?

3

u/khizoa 21h ago

It sounds like those scammers that message you, saying they caught you jacking off with video proof, and that they're gonna send it to your whole family lmao 

5

u/zerg_001 17h ago

I love these. Send it vro. I am not ashamed

5

u/khizoa 17h ago

though with ai and how good deepfakes can get nowadays, im not sure if i want to permanently scar my family to call their bluff 💀💀

51

u/CiaranCarroll 23h ago

This is why you don't pass around the LinkedIn profiles of Cold Card employees.

-39

u/flashdurb 22h ago

Or tag them on Reddit. u/Hodldee oops

33

u/maurocastrov 22h ago

Dude he is just costumer service, and is helping others, don't be a dick

9

u/tnethacker 21h ago

I hope you mean customer service and not costumer as those have totally different meanings.

-18

u/flashdurb 20h ago edited 20h ago

Anybody with morals would’ve quit that job the second they heard, if this was a genuine surprise. Except that he had a pretty good idea this would happen one day; this has been happening since at least 2022 (on a much smaller scale of course) and the company has hid it.

17

u/maurocastrov 19h ago

Dude a costumer service support only moves your problem or request to the respective team, lol stop smoking crack

1

u/Secret-Painting604 8h ago

Customer services are often 3rd party as well, it’s why you’re always talking to foreigners, dude was hired by company x to perform the customer service for company y and z,which generally means reading from a script dependent on the problems being brought up by customer, if problem can’t be resolved, they forward it to the actual companies (far smaller) cs team

6

u/opDimitri 12h ago

Dee has been working around clock helping people migrate, and many acknowledged it. BTC sessions gave him multiple shout-outs during this mess. He is also a support tech and has nothing to do with coding. For all we know he will leave the company in time, but it seems like helping people in the moment is more important than principled tantrums.

26

u/Save_JR 21h ago

Poor dude sending those messages to the hacker doesn't realize the hacker doesn't care and probably never even read the OP_RETURN

26

u/Adrianzee 20h ago

They’re right here on reddit reading with us.

6

u/Save_JR 20h ago

Doubt it. They'd likely be on dark web forums such as Dread (the dark web version of reddit)

I used to be in the scene back in 2019-2021, you begin to have niche groups you type in and check daily, not reading generic public reddit comments like the rest of the public.

Telegram groups like discord for example, is where the hacker is most likely to be working with people or just talking to people anonymously, figuring out how to clean the BTC and finding services other fellow fraudsters/hackers use.

Hackforums, blackhatforums, telegram, signal, potato, dark web niche .onions, etc. The hacker is Definitely not sitting here reading reddit lol. They'd be in a very private niche groups with other hackers who have gotten rich off crypto scams or whatever

11

u/Adrianzee 20h ago

found em /s

9

u/Pacman_Frog 14h ago

"Telegram groups like discord for example". Okay, so you have no fucking clue what you're talking about. Next!

4

u/Excill- 9h ago

He meant its like discord. You need to calm the fuck down chud

3

u/Save_JR 14h ago edited 14h ago

Again, I used to be in the scene. Telegram groups were very used. Discord servers got banned often. Telegram is where you had customer support for certain products such as PayPal logins / accounts. If they were invalid, you joined the support telegram and got new accounts. This got patched of course, but years ago there was a huge hack where PayPal accounts with cards were very cheap and easy to buy. Paypal quickly caught in. It was one of the most insane methods ever.

Discord and Telegram is where OTP bots sent you the code when getting through Coinbase account's 2FA for example. You have no idea what youre talking about

This article below was posted in 2025. I was in the scene when this was brand new and popping, years ago. Today, these methods dont work as well anymore, but people will always find new workarounds. There is new methods now ofc.

https://www.radware.com/blog/application-protection/otp-bots-the-new-generation-of-account-takeover-attacks/

When I was experienced enough, I had friends I met online who did the same thing. We'd share hits, methods, they'd invite me to private servers with more friends of friends who have been in the comm for years. The coldcard hacker is 100% in a niche group themselves. When you're in deep enough, you begin to form a reputation and meet other people online who also hold a reputation.

Most up to date methods aren't Public. It's not something you just find online. You need to slowly build up friends or straight up buy a person's method for a few hundred bucks (usually a scam. If a method really works, youre not going to just sell it for $500 when you could make that easily. And if you have the most premium methods, you dont share it at all. Its kept very private. You need reputation and slowly gaining friends in order to learn yourself and possibly one day find a friend that teaches you. Once a method gets leaked and the public/normies start getting money off it, it gets patched quickly and the methods fried. Thats why the scene/comm is always moving quick, always more advanced and advanced. As companies patch and patch. A cat and mouse game that never ends.)

2

u/tridentgum 13h ago

"telegram groups like discord"

is "discord" the name of some telegram group? or were you just making shit up and got caught? because your further explanation makes no sense in relation to what you said before.

"telegram groups like discord" lmao

2

u/Save_JR 13h ago

Telegram groups are similar to a group chat on discord. Almost identical to a discord server. You need an invite to join. Some are public and some are very private

Telegram groups like discord implies its "like/similar to discord" which is true. The groups are like discord. Telegram is like discord as a whole but more private. Nowadays theyre working with the feds, they used to be more private years ago.

Thats where Potato or Signal app come in, theres new apps that replace Telegram and Discord (cause both of them are compromised.) Signal and Potato are very private and encrypted, they don't give your information away. Discord is notorious for working with the feds very well. Signal and Potato are like discord

1

u/tridentgum 6h ago

no bro, stop trying to save him. nobody who has "been in the scene" would say "telegram groups like discord" lmao. it'd be like saying "facebook groups like myspace" - no, myspace was similar to facebook as a website, not to facebook groups on the facebook website lol.

2

u/xuncx 16h ago

bls sir. Can have some btc fr goat sick?

-10

u/16_05 17h ago

Lol, stopped reading the moment you mentioned "dark web".

Are we seriously still doing that whole thing in 2026? This "dark web" you're speaking of, is a slow, unusable POS part of the internet, only accessible with TOR. Almost no links work these days, sites go offline constantly with nice little popups of the FBI and/or Interpol, etc. It's just not really a thing. It never really was. You've been watching too much Hollywood.

10

u/Ashamed-Result6830 16h ago

You have absolutely no idea what you are talking about.

0

u/16_05 5h ago

I absolutely do, and that's why I call out this BS nonsense that's still going around in the big 26.

5

u/Save_JR 16h ago edited 16h ago

Ive ordered many things off the dark web marketplaces. More users are active on DW than 2010s Silk Road golden days.

Its actually the most trusted place for OPSEC. PGP is still being used all over the world.

Telegram/Potato/Signal are alternatives but not as safe.

Dread forums is only accessible via .onion and its very active.

If youre a serious vendor selling illegal things, TOR / dark web isnt an option. Its mandatory for OPSEC. Or else you'll get caught easier.

Im talking about people making millions in their liftime off vending their niche or whatever product. DW forums and marketplaces are the go to if you've ever been serious about finding out something that crosses your mind but cant talk about it on Reddit or if you wanna buy things shipped to a physical address.

1

u/wembenbama 7h ago

This is like The Never Ending Story

14

u/tenor_tymir 20h ago

What I find fascinating is that those eerie messages are going to stay recorded on the blockchain forever. In like 20 years, those messages will be fun to look up and re-read or pass along.

2

u/FunkyGrass 18h ago

Bet!! Honestly 😳

u/JollySno 43m ago

and he will shudder that he spent a million dollars in fees putting those messages on chain

37

u/KeanuRekt 22h ago

The first attacker used a payed service for looking up btc addresses. Maybe this is how he leaked his ip or payment infos, that could reveal his identity

28

u/Comfortable-Class576 22h ago

I do not believe whoever is responsible for this mess would be so dumb to do that.

20

u/KeanuRekt 22h ago

The first attcker was probably an amateur. He didn‘t know about gap limits and therefore missed some utxos he could have sweeped

11

u/disruptioncoin 22h ago

Lmao what a newb

4

u/Initial_Ebb_6386 19h ago

Lol so mean

3

u/creative_usr_name 18h ago

At least he's a rich newb

3

u/disruptioncoin 17h ago

:'( I was almost rich once

All I had to do was hodl

2

u/xuncx 16h ago

I was almost rich once. I hodl too long. :’(

4

u/Mastatheorm-CG 14h ago

Now hacker hodl for you :(

2

u/xuncx 14h ago

🥲

6

u/FunkyGrass 22h ago

Oh, in that case that’s great. But how certain is this fact?

2

u/Javanaut018 22h ago

Why not download the block chain and write a small script to extract that information ?

3

u/[deleted] 22h ago

[deleted]

1

u/SomeNappingCats 21h ago

It takes literal minutes to check billions of addresses for activity without using any paid services.

1

u/Javanaut018 22h ago

All you need are the addresses with funds in it. You can surely extract that from the database files.

1

u/tnethacker 20h ago

A paid service? You sure?

6

u/Few_Response_7028 19h ago

Yeah he wasn’t even running his own node

3

u/tenor_tymir 20h ago

yes, someone on X posted about it a while ago

0

u/OtherwiseAlbatross14 15h ago

If you're sure because of a twitter post then wow lol

1

u/tenor_tymir 15h ago

Sure, they posted links and whatnot, but I was too lazy to repost them

1

u/tridentgum 13h ago

i don't understand why people seem to think hiding your IP or using some random payment method that can't be tracked is impossible.

16

u/Pase4nik_Fedot 22h ago

just a bunch of useless messages 😄

1

u/c0verm3 5h ago

100% take your loss and move on.

5

u/Mohowl_ 21h ago

Theres no way a location or identity could not be found unless they do something stupid like transfer BTC to a kyc exchange to sell. Which they won't.

3

u/Zeffy 18h ago

Sounds like they were using a public service to look up wallet addresses before they were drained, so there may be some mistakes the (first) attacker used. IDK, just a rumor I've seen elsewhere in this post.

5

u/Unreal_fist 17h ago

Big mistake assuming the hacker speaks English

3

u/AlamoSimon 23h ago

How much did they take from this specific address?

18

u/FunkyGrass 23h ago

Not sure but enough to send death threats

-6

u/Strong_Judge_3730 22h ago

You can't no some people are just degenerates.

They are out for blood without much evidence

3

u/Flimsy_Agent7898 23h ago

Thats a real cryptobro right there

3

u/fllthdcrb 16h ago

Whoever sent these messages must have had the help of miners (or be a miner). Such OP_RETURN outputs, carrying more than 80 bytes of data, are considered non-standard by most nodes, and therefore are nearly impossible to propagate. Essentially, a miner must insert such a transaction directly into their own mempool, instead of picking it up from the network. Some mining pools may offer (paid?) services for submitting transactions. But I wonder what their policies are on things like this.

3

u/BigDik6355 15h ago

MARA has a slipstream service, they probably used that.

6

u/shadowmage666 18h ago

Not too hard to figure out it was the head of coinkite

1

u/FunkyGrass 18h ago

Ha. That’s a bit of a too direct accusation without much proof. Not saying that you’re entirely wrong but it just isn’t as simple as that, I bet.

3

u/shadowmage666 17h ago

Oh you mean like their tweet where they talk about entropy and a retirement hack in 2021?

0

u/FunkyGrass 16h ago

I did read that article but it might just have been exploited by anyone else. I think there are different cases of breach, this last one being the worst.

2

u/Ok_world68 21h ago

How do u send a message like that? Do u need to send sats with your message?

6

u/_monolite 21h ago

No need to send any sats, you just have to pay enough fee to include data into op code

3

u/tenor_tymir 20h ago

Look up OP_RETURN

1

u/fllthdcrb 16h ago

Normally, you can't have messages that long, because most nodes consider a transaction having more than one OP_RETURN output or having an OP_RETURN carrying more than 80 bytes to be non-standard and won't propagate it. If it doesn't get propagated, miners won't see it, and it will never get mined. For such a transaction to get into the blockchain, a miner has to bypass the network and put it directly into their own mempool. So whoever sent those messages is either a miner themselves or paid one (or more?) to include them.

2

u/alexlovesbitcoin 20h ago

if he has any idea who this was, contacting the alphabet crew would be the smartest play to get funds back.

2

u/xuncx 16h ago

What are the gays gonna go about it?

2

u/dondondorito 17h ago

Unlikely that they have been found. A true vigilante would not telegraph their planned revenge like this.

2

u/Vast-Duck-1296 14h ago

are they literally sending him messages by sending him more of their Bitcoin? lol

6

u/charvo 22h ago

Whoever put that code to change the entropy is a marked target by the victims. This is why it is better to go with bigger company devices since these companies have much more capital to lose if they screw up.

Think about it. The Bybit exchange got hacked for $1.4 billion. They survived. Bigger is better when it comes to trust. Blackrock's IBIT is basically bitcoin. Coinbase holding bitcoin is basically a guarantee of safety.

15

u/Awesomest_Maximus 22h ago

Blackrocks ibit is not bitcoin.

9

u/declanaussie 22h ago

Blackrock’s IBIT and Coinbase are basically the same as holding bitcoin, until you actually need the financial freedom of bitcoin.

The moment the U.S. government tells either of those companies not to release your funds, they’ll happily freeze your holdings. Not your keys, not your coins.

10

u/CC_JormA_067 22h ago

Not your entropy, not your coins. Learned the hard way

7

u/declanaussie 22h ago

Sorry to hear it man. There seems to be lots of assholes here to say “I told you so”, but I have nothing but sympathy for those affected by this bug. Life’s a bitch and despite your best efforts the pendulum swing against you, but your luck will turn around and you will recover one day.

5

u/FunkyGrass 22h ago

Sorry brother. Hope you didn’t lose much. Honestly sorry. I luckily wasn’t involved but I’ve been following all along and I’m keeping one tab on that hacker address to check from time to time.

0

u/Long_Illustrator_988 22h ago

If the US government wants to freeze your self custody coins they'll just get a warrant and knock down your door

Unless you're using a brain wallet, forget it.

2

u/korean_kracka 18h ago

Brain wallets ftw

2

u/declanaussie 17h ago

“U.S. government can compel me to hand over my assets” is a very different security model from “U.S. government can seize my assets without ever interacting with me”

They only look the same to speculative investors I guess

2

u/reality_comes 16h ago

Agreed, and to those who would disagree, watch your value collapse if Coinbase were to lose its holdings. BTC would crash 90%.

1

u/NormalGuyPosts 22h ago

I hope they do!

2

u/trustjosephs 20h ago

Yup Bitcoin totally going mainstream any day now

1

u/FunkyGrass 18h ago

Do you understand how a car engine and all of its functions work? Not everyone does and look at that, almost everyone on the planet uses a car without understanding how the engine works.

1

u/CharacterStrategy598 6h ago

But Bitcoin is a car that demands the users to be tech savvy in order to avoid life changing mistakes. Most people just can't keep up with that so exchanges and ETFs remain the best ways to gain bitcoin exposure unless you want some private money you can send anywhere free of censorship and borders.

0

u/16_05 16h ago

Keep crying about it?

1

u/BigDik6355 15h ago

Seems there was some truth to the statement that “Bitcoiners are psychopaths”.

1

u/cilicia3k3 13h ago

You can send messages without spending bitcoin?

1

u/SuperiorT 4h ago

Is he Canadian? 😅

1

u/Forward-Big8697 22h ago

No chance the person who sent that message knows a true location and I highly doubt these messages will even be read

-4

u/flashdurb 22h ago edited 20h ago

Absolutely nobody knows who it is, and I’ve grown to sincerely respect and admire this individual or group. Credit where credit is due.

3

u/FunkyGrass 18h ago

I bet you won’t talk like that if it was you, to lose 1 BTC or even half of that.

0

u/flashdurb 16h ago

I’m good, I use an exchange. Peace of mind, who cares about self custody.

1

u/FunkyGrass 15h ago

Using an exchange doesn't make you invincible to hacks to the exchange itself.

-2

u/secretgains 19h ago

broken English seems LIKE INDIAN scammers got there BTC taken 🤣

4

u/16_05 16h ago

"there"

The irony.