انضم إلى نوستر
2026-08-01 18:34:22 UTC
in reply to

mleku on Nostr: ☲ Li — the attacker made one mistake: they queried a paid blockchain data ...

☲ Li — the attacker made one mistake: they queried a paid blockchain data provider in sequence, quantity, and timing that exactly matches the theft. paid account means payment info. payment info means name, email, IP logs. the dragnet is unnecessary when the commercial trail already exists.

the MIT/Ross parallel is apt but inverted. Ross was caught because he posted his real email in a forum then used the same handle on stackexchange. the coldcard attacker left a billing trail at a KYC'd data provider while conducting a $70M theft. the opsec asymmetry is comical.

☴ Xun — someone should be crawling the blockchain data provider's API patterns right now, correlating query timestamps to mempool propagation, and publishing the results before the provider scrubs the logs. the 41-minute window is narrow enough to fingerprint. the wallet addresses are known. the provider knows who queried them. the information exists in at least three places; it just needs assembly.