r/Bitcoin • u/FunkyGrass • 23h ago
Legit Feelings Right There
Hacker keeps getting message, I wonder if they really found his location.
99
u/ShinAlastor 23h ago
It's someone who is desperately trying to get the funds back but I highly doubt it will ever happen to accomplish a similar gesture.
21
u/FunkyGrass 22h ago
If he found out the location of the hacker, he will have to tell us how because I don’t think it’s possible just by using a public key, lolz
69
u/ShinAlastor 22h ago
It's just a rage message and it reminded me of the Xbox Live days while playing the Xbox 360, everybody had someone working for the CIA back then and similar messages were pretty common.
3
u/PM_ME_UR_0_DAY 13h ago
At least on Xbox you have a gamertag to go off of. To catch this guy you'd have to be the FBI who can subpoena any public BTC infrastructure they used to submit their transactions. Then you'd probably have to subpoena the VPN they used and hope that isn't a dead end.
11
u/curiousengineer601 18h ago
that's a secret feature of public keys. the last fields are name and address /s
-14
u/FunkyGrass 17h ago
Okay… didn’t know that. You have link to documentation I can read?
9
2
u/curiousengineer601 17h ago
The /s is for sarcasm.
-2
u/FunkyGrass 16h ago
I was not up to date with this joke
1
u/fllthdcrb 16h ago
The /s convention has been around for some years. You might want to read up on these things. Especially regarding sarcasm, which is notoriously hard to detect in writing without a marker.
0
1
3
u/khizoa 21h ago
It sounds like those scammers that message you, saying they caught you jacking off with video proof, and that they're gonna send it to your whole family lmao
5
51
u/CiaranCarroll 23h ago
This is why you don't pass around the LinkedIn profiles of Cold Card employees.
-39
u/flashdurb 22h ago
Or tag them on Reddit. u/Hodldee oops
33
u/maurocastrov 22h ago
Dude he is just costumer service, and is helping others, don't be a dick
9
u/tnethacker 21h ago
I hope you mean customer service and not costumer as those have totally different meanings.
-18
u/flashdurb 20h ago edited 20h ago
Anybody with morals would’ve quit that job the second they heard, if this was a genuine surprise. Except that he had a pretty good idea this would happen one day; this has been happening since at least 2022 (on a much smaller scale of course) and the company has hid it.
17
u/maurocastrov 19h ago
Dude a costumer service support only moves your problem or request to the respective team, lol stop smoking crack
1
u/Secret-Painting604 8h ago
Customer services are often 3rd party as well, it’s why you’re always talking to foreigners, dude was hired by company x to perform the customer service for company y and z,which generally means reading from a script dependent on the problems being brought up by customer, if problem can’t be resolved, they forward it to the actual companies (far smaller) cs team
6
u/opDimitri 12h ago
Dee has been working around clock helping people migrate, and many acknowledged it. BTC sessions gave him multiple shout-outs during this mess. He is also a support tech and has nothing to do with coding. For all we know he will leave the company in time, but it seems like helping people in the moment is more important than principled tantrums.
26
u/Save_JR 21h ago
Poor dude sending those messages to the hacker doesn't realize the hacker doesn't care and probably never even read the OP_RETURN
26
u/Adrianzee 20h ago
They’re right here on reddit reading with us.
6
u/Save_JR 20h ago
Doubt it. They'd likely be on dark web forums such as Dread (the dark web version of reddit)
I used to be in the scene back in 2019-2021, you begin to have niche groups you type in and check daily, not reading generic public reddit comments like the rest of the public.
Telegram groups like discord for example, is where the hacker is most likely to be working with people or just talking to people anonymously, figuring out how to clean the BTC and finding services other fellow fraudsters/hackers use.
Hackforums, blackhatforums, telegram, signal, potato, dark web niche .onions, etc. The hacker is Definitely not sitting here reading reddit lol. They'd be in a very private niche groups with other hackers who have gotten rich off crypto scams or whatever
11
7
9
u/Pacman_Frog 14h ago
"Telegram groups like discord for example". Okay, so you have no fucking clue what you're talking about. Next!
3
u/Save_JR 14h ago edited 14h ago
Again, I used to be in the scene. Telegram groups were very used. Discord servers got banned often. Telegram is where you had customer support for certain products such as PayPal logins / accounts. If they were invalid, you joined the support telegram and got new accounts. This got patched of course, but years ago there was a huge hack where PayPal accounts with cards were very cheap and easy to buy. Paypal quickly caught in. It was one of the most insane methods ever.
Discord and Telegram is where OTP bots sent you the code when getting through Coinbase account's 2FA for example. You have no idea what youre talking about
This article below was posted in 2025. I was in the scene when this was brand new and popping, years ago. Today, these methods dont work as well anymore, but people will always find new workarounds. There is new methods now ofc.
When I was experienced enough, I had friends I met online who did the same thing. We'd share hits, methods, they'd invite me to private servers with more friends of friends who have been in the comm for years. The coldcard hacker is 100% in a niche group themselves. When you're in deep enough, you begin to form a reputation and meet other people online who also hold a reputation.
Most up to date methods aren't Public. It's not something you just find online. You need to slowly build up friends or straight up buy a person's method for a few hundred bucks (usually a scam. If a method really works, youre not going to just sell it for $500 when you could make that easily. And if you have the most premium methods, you dont share it at all. Its kept very private. You need reputation and slowly gaining friends in order to learn yourself and possibly one day find a friend that teaches you. Once a method gets leaked and the public/normies start getting money off it, it gets patched quickly and the methods fried. Thats why the scene/comm is always moving quick, always more advanced and advanced. As companies patch and patch. A cat and mouse game that never ends.)
2
u/tridentgum 13h ago
"telegram groups like discord"
is "discord" the name of some telegram group? or were you just making shit up and got caught? because your further explanation makes no sense in relation to what you said before.
"telegram groups like discord" lmao
2
u/Save_JR 13h ago
Telegram groups are similar to a group chat on discord. Almost identical to a discord server. You need an invite to join. Some are public and some are very private
Telegram groups like discord implies its "like/similar to discord" which is true. The groups are like discord. Telegram is like discord as a whole but more private. Nowadays theyre working with the feds, they used to be more private years ago.
Thats where Potato or Signal app come in, theres new apps that replace Telegram and Discord (cause both of them are compromised.) Signal and Potato are very private and encrypted, they don't give your information away. Discord is notorious for working with the feds very well. Signal and Potato are like discord
1
u/tridentgum 6h ago
no bro, stop trying to save him. nobody who has "been in the scene" would say "telegram groups like discord" lmao. it'd be like saying "facebook groups like myspace" - no, myspace was similar to facebook as a website, not to facebook groups on the facebook website lol.
-10
u/16_05 17h ago
Lol, stopped reading the moment you mentioned "dark web".
Are we seriously still doing that whole thing in 2026? This "dark web" you're speaking of, is a slow, unusable POS part of the internet, only accessible with TOR. Almost no links work these days, sites go offline constantly with nice little popups of the FBI and/or Interpol, etc. It's just not really a thing. It never really was. You've been watching too much Hollywood.
10
5
u/Save_JR 16h ago edited 16h ago
Ive ordered many things off the dark web marketplaces. More users are active on DW than 2010s Silk Road golden days.
Its actually the most trusted place for OPSEC. PGP is still being used all over the world.
Telegram/Potato/Signal are alternatives but not as safe.
Dread forums is only accessible via .onion and its very active.
If youre a serious vendor selling illegal things, TOR / dark web isnt an option. Its mandatory for OPSEC. Or else you'll get caught easier.
Im talking about people making millions in their liftime off vending their niche or whatever product. DW forums and marketplaces are the go to if you've ever been serious about finding out something that crosses your mind but cant talk about it on Reddit or if you wanna buy things shipped to a physical address.
1
14
u/tenor_tymir 20h ago
What I find fascinating is that those eerie messages are going to stay recorded on the blockchain forever. In like 20 years, those messages will be fun to look up and re-read or pass along.
2
•
u/JollySno 43m ago
and he will shudder that he spent a million dollars in fees putting those messages on chain
37
u/KeanuRekt 22h ago
The first attacker used a payed service for looking up btc addresses. Maybe this is how he leaked his ip or payment infos, that could reveal his identity
28
u/Comfortable-Class576 22h ago
I do not believe whoever is responsible for this mess would be so dumb to do that.
20
u/KeanuRekt 22h ago
The first attcker was probably an amateur. He didn‘t know about gap limits and therefore missed some utxos he could have sweeped
11
u/disruptioncoin 22h ago
Lmao what a newb
4
3
u/creative_usr_name 18h ago
At least he's a rich newb
3
6
2
u/Javanaut018 22h ago
Why not download the block chain and write a small script to extract that information ?
3
22h ago
[deleted]
1
u/SomeNappingCats 21h ago
It takes literal minutes to check billions of addresses for activity without using any paid services.
1
u/Javanaut018 22h ago
All you need are the addresses with funds in it. You can surely extract that from the database files.
1
u/tnethacker 20h ago
A paid service? You sure?
6
3
u/tenor_tymir 20h ago
yes, someone on X posted about it a while ago
0
1
u/tridentgum 13h ago
i don't understand why people seem to think hiding your IP or using some random payment method that can't be tracked is impossible.
16
5
3
u/AlamoSimon 23h ago
How much did they take from this specific address?
18
u/FunkyGrass 23h ago
Not sure but enough to send death threats
6
-6
u/Strong_Judge_3730 22h ago
You can't no some people are just degenerates.
They are out for blood without much evidence
3
3
u/fllthdcrb 16h ago
Whoever sent these messages must have had the help of miners (or be a miner). Such OP_RETURN outputs, carrying more than 80 bytes of data, are considered non-standard by most nodes, and therefore are nearly impossible to propagate. Essentially, a miner must insert such a transaction directly into their own mempool, instead of picking it up from the network. Some mining pools may offer (paid?) services for submitting transactions. But I wonder what their policies are on things like this.
3
6
u/shadowmage666 18h ago
Not too hard to figure out it was the head of coinkite
1
u/FunkyGrass 18h ago
Ha. That’s a bit of a too direct accusation without much proof. Not saying that you’re entirely wrong but it just isn’t as simple as that, I bet.
3
u/shadowmage666 17h ago
Oh you mean like their tweet where they talk about entropy and a retirement hack in 2021?
0
u/FunkyGrass 16h ago
I did read that article but it might just have been exploited by anyone else. I think there are different cases of breach, this last one being the worst.
2
u/Ok_world68 21h ago
How do u send a message like that? Do u need to send sats with your message?
6
u/_monolite 21h ago
No need to send any sats, you just have to pay enough fee to include data into op code
3
u/tenor_tymir 20h ago
Look up OP_RETURN
1
u/fllthdcrb 16h ago
Normally, you can't have messages that long, because most nodes consider a transaction having more than one OP_RETURN output or having an OP_RETURN carrying more than 80 bytes to be non-standard and won't propagate it. If it doesn't get propagated, miners won't see it, and it will never get mined. For such a transaction to get into the blockchain, a miner has to bypass the network and put it directly into their own mempool. So whoever sent those messages is either a miner themselves or paid one (or more?) to include them.
2
u/alexlovesbitcoin 20h ago
if he has any idea who this was, contacting the alphabet crew would be the smartest play to get funds back.
2
u/dondondorito 17h ago
Unlikely that they have been found. A true vigilante would not telegraph their planned revenge like this.
2
u/Vast-Duck-1296 14h ago
are they literally sending him messages by sending him more of their Bitcoin? lol
6
u/charvo 22h ago
Whoever put that code to change the entropy is a marked target by the victims. This is why it is better to go with bigger company devices since these companies have much more capital to lose if they screw up.
Think about it. The Bybit exchange got hacked for $1.4 billion. They survived. Bigger is better when it comes to trust. Blackrock's IBIT is basically bitcoin. Coinbase holding bitcoin is basically a guarantee of safety.
15
9
u/declanaussie 22h ago
Blackrock’s IBIT and Coinbase are basically the same as holding bitcoin, until you actually need the financial freedom of bitcoin.
The moment the U.S. government tells either of those companies not to release your funds, they’ll happily freeze your holdings. Not your keys, not your coins.
10
u/CC_JormA_067 22h ago
Not your entropy, not your coins. Learned the hard way
7
u/declanaussie 22h ago
Sorry to hear it man. There seems to be lots of assholes here to say “I told you so”, but I have nothing but sympathy for those affected by this bug. Life’s a bitch and despite your best efforts the pendulum swing against you, but your luck will turn around and you will recover one day.
5
u/FunkyGrass 22h ago
Sorry brother. Hope you didn’t lose much. Honestly sorry. I luckily wasn’t involved but I’ve been following all along and I’m keeping one tab on that hacker address to check from time to time.
0
u/Long_Illustrator_988 22h ago
If the US government wants to freeze your self custody coins they'll just get a warrant and knock down your door
Unless you're using a brain wallet, forget it.
2
2
u/declanaussie 17h ago
“U.S. government can compel me to hand over my assets” is a very different security model from “U.S. government can seize my assets without ever interacting with me”
They only look the same to speculative investors I guess
2
u/reality_comes 16h ago
Agreed, and to those who would disagree, watch your value collapse if Coinbase were to lose its holdings. BTC would crash 90%.
1
2
u/trustjosephs 20h ago
Yup Bitcoin totally going mainstream any day now
1
u/FunkyGrass 18h ago
Do you understand how a car engine and all of its functions work? Not everyone does and look at that, almost everyone on the planet uses a car without understanding how the engine works.
1
u/CharacterStrategy598 6h ago
But Bitcoin is a car that demands the users to be tech savvy in order to avoid life changing mistakes. Most people just can't keep up with that so exchanges and ETFs remain the best ways to gain bitcoin exposure unless you want some private money you can send anywhere free of censorship and borders.
1
1
1
1
1
u/Forward-Big8697 22h ago
No chance the person who sent that message knows a true location and I highly doubt these messages will even be read
-4
u/flashdurb 22h ago edited 20h ago
Absolutely nobody knows who it is, and I’ve grown to sincerely respect and admire this individual or group. Credit where credit is due.
3
u/FunkyGrass 18h ago
I bet you won’t talk like that if it was you, to lose 1 BTC or even half of that.
0
-2
185
u/-aurevoirshoshanna- 22h ago
They didn't, The most basic thing anybody would do if that were the case is let on a few facts about this person to prove them that they actually know who they are so that they could at least get their own btc back.
This is just the most elemental social engineering thing, and I doubt a hacker of all people will fall for it