3 ms·
> but the fact that there are three waves in the attack shows the level of coordination and pre-planning that was involved in making it happen. That's a strang
by CodesInChaos 2mo ago
> but the fact that there are three waves in the attack shows the level of coordination and pre-planning that was involved in making it happen.
That's a strange interpretation. If it was planned well, why weren't all affected addresses drained as quickly as possible? I would have continuously emptied all vulnerable addresses, from highest to lowest without taking a break in the middle.
> Instead of picking the lowest cost option, the attacker appears to be prioritizing speed in an apparent move to make themselves as untraceable as possible.
I don't see how higher fees would make the attacker less traceable. If anything, the unusually high fees stand out. Though in the long run defenders will enumerate all the vulnerable source addresses anyway, so the affected coins are inherently traceable (at least until laundered).
More likely they prioritized speed to beat other attackers, now that the vulnerability is public. No matter if this was the original attacker or a competitor.
- Scoundreller 2mo agoMore likely the higher fees forces through the transaction faster. If it sits around waiting for a miner to pick it up, there's a chance the real owner or competitor could replace-by the transaction with a higher fee and redirect it. Instead of writing that logic, just make sure it gets into the next block before anyone catches on.
- markjenkinswpg 2mo agoOne reason for waves is that end-users had the option to add additional entropy via dice rolls mixed in with the bad internals or an arbitrary BIP39 passphrase mixed in after the initial 12-24 word seed phrase is output. With the level of paranoia culture around the Cold Card, it wouldn't have been too uncommon for folks to take one or more of these additional measures. How much effective entropy someone adds these ways would vary. When you're told the initial entropy is solid, what's the point of adding too much of your own? Long passphrases on top of seeds are also seen as a good way to cause a loss by forgetting and also a usability PITA that takes away some of the convenience of a hardware wallet. Some folks no doubt opted for short BIP39 passphrases just as a means of protecting against a situation where someone else in their household stumbles upon a paper or metal backup of a seed but doesn't know anything about the cracking required to try BIP39 passphrases. Main reason these extra sources of entropy would be grabbed in waves is different bad actors coming along and making the extra effort after the disclosure. The website cktripwire.com has a nice dashboard of honeypot bitcoin put out there with the extra entropy. So far only low amounts of additional entropy like 1-5 dice rolls or one extra passphrase word have been swept, though this honeypot was published after additional waves. More will certainly swept in the end.