COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

Operator attribution report

clay-attribution

https://x.com/clay_garrett/status/2083247006139503065

Captured screenshot of the post by @clay_garrett, posted 31 Jul 2026, 17:42 UTC
@clay_garrett posted captured full-size capture → original post →

Latest reviewed change

source content difference between and

Asanoha's display name changed to include 'Timechain Art Magazine', and the reply by IphigenAleksy to that account is no longer present in a same-depth capture (37 scroll rounds).

seen +1 -11 full history below
 post: 2083353279573155874
 role: reply
 author: asanoha_gold
-name: Asanoha
+name: Asanoha | Timechain Art Magazine
 created: 2026-08-01T00:45:03Z
 media: 0
 body:

First lines only. The complete diff is in the timeline below.

Author
@clay_garrett
Organisation
Block
Evidence role
social statement
Posted
Capture status
capture held

Block's report that the operator used a paid blockchain-services account; the complete thread says the provider's logs matched the workflow and that Block saw no evidence of knowing participation.

This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .

The conversation

Captured . 2 continuation posts, 166 replies held, 75 muted as low signal. Posts are in the archive's own order, oldest first, not the order X ranks them in.

  1. @clay_garrett the registered post 31 Jul 2026, 17:42 UTC
    Captured screenshot of the post by @clay_garrett

    capture taken

  2. @clay_garrett same author, continuing 31 Jul 2026, 17:42 UTC
    Captured screenshot of the post by @clay_garrett

    capture taken

  3. @clay_garrett same author, continuing 31 Jul 2026, 17:42 UTC
    Captured screenshot of the post by @clay_garrett

    capture taken

Replies are unmoderated third-party material, reproduced here as part of the record. Inclusion is not endorsement, and nothing in them has been checked by this project.
Replies held in this capture (166)

Low-signal replies are collapsed to one line, never removed. A reply is collapsed only on mechanical grounds: fewer than 40 characters, no text, mentions only, no letters or digits, a bare link, or text identical to another reply in the same capture. What a reply argues is never a reason. Each one says which rule collapsed it, and its screenshot is one click away.

  1. Captured screenshot of the reply by @spacetimedb

    capture taken

  2. Captured screenshot of the reply by @Tangem

    capture taken

  3. Captured screenshot of the reply by @CMCMarketsAusNZ

    capture taken

  4. Captured screenshot of the reply by @bodyfastapp

    capture taken

  5. Get sophisticated.
    show the capture Captured screenshot of the reply by @buttonxyz

    capture taken

  6. Captured screenshot of the reply by @attio

    capture taken

  7. Captured screenshot of the reply by @jobescape_ai

    capture taken

  8. Captured screenshot of the reply by @Starlink

    capture taken

  9. @AJ__1337 31 Jul 2026, 17:46 UTC
    Captured screenshot of the reply by @AJ__1337

    capture taken

  10. Captured screenshot of the reply by @BitcoinCoderBob

    capture taken

  11. @humble21m 31 Jul 2026, 17:50 UTC under 40 characters
    Wow
    show the capture Captured screenshot of the reply by @humble21m

    capture taken

  12. @mercalerta 31 Jul 2026, 17:54 UTC
    Captured screenshot of the reply by @mercalerta

    capture taken

The remaining 154 replies
  1. We didn’t even ran his full node to query the utxo set. This just shows how novice the attacker is
    show the capture Captured screenshot of the reply by @joaodealmeida_

    capture taken

  2. @beeforbacon1 31 Jul 2026, 18:06 UTC under 40 characters
    go get em, champ.
    show the capture Captured screenshot of the reply by @beeforbacon1

    capture taken

  3. @0xkuncoro 31 Jul 2026, 18:15 UTC
    Worth pairing with the chain state: none of it has moved. The consolidation address is at 4 transactions and 56,202,005,440 sats received with zero spent. A paid account trail on one side and a fully tagged, unmoved pile on the other is a bad place to be sitting.
    show the capture Captured screenshot of the reply by @0xkuncoro

    capture taken

  4. @willcole 31 Jul 2026, 18:18 UTC identical to another reply in this capture
    Awesome work Clay
    show the capture Captured screenshot of the reply by @willcole

    capture taken

  5. @Bob_Croft 31 Jul 2026, 18:18 UTC
    @grok - please explain what the service provider gave up that assisted in this attack. Is it related to KYC at an exchange?
    show the capture Captured screenshot of the reply by @Bob_Croft

    capture taken

  6. @JoeNakamoto 31 Jul 2026, 18:21 UTC this account is registered elsewhere in the record
    So the hacker wasn’t even a very good one.., and still stole MILLIONS?!!
    show the capture Captured screenshot of the reply by @JoeNakamoto

    capture taken

  7. @MaxAAndrew 31 Jul 2026, 18:23 UTC
    Way to go! Go get em! The chances are slim but it would be such a great ending to find and return every stack and hold this/these loser(s) accountable.
    show the capture Captured screenshot of the reply by @MaxAAndrew

    capture taken

  8. @currentseas 31 Jul 2026, 18:25 UTC
    Amazing work. If this ends up with people's funds being returned, you'll never again need to buy your own beer at a conference. You'll probably also have the offer of free BJs for life from nvk, but personally I'd just take the beer.
    show the capture Captured screenshot of the reply by @currentseas

    capture taken

  9. @DonalDevine 31 Jul 2026, 18:27 UTC under 40 characters
    http:// Mempool.space?
    show the capture Captured screenshot of the reply by @DonalDevine

    capture taken

  10. @OttawaGestapo 31 Jul 2026, 18:28 UTC under 40 characters
    wowee
    show the capture Captured screenshot of the reply by @OttawaGestapo

    capture taken

  11. @r0bertclarkson 31 Jul 2026, 18:29 UTC under 40 characters
    Vibe coder confirmed
    show the capture Captured screenshot of the reply by @r0bertclarkson

    capture taken

  12. @Nneuman 31 Jul 2026, 18:29 UTC this account is registered elsewhere in the record
    great find. hope this helps identify the bad actor
    show the capture Captured screenshot of the reply by @Nneuman

    capture taken

  13. Maybe that means it could be a white hat, who has been quiet so far. Doesn't explain the sloppiness. Or they just used Tor/VPN, and not much will be found.
    show the capture Captured screenshot of the reply by @TomZarebczan

    capture taken

  14. @hellaxbt 31 Jul 2026, 18:33 UTC
    @grok so who is the service provider then?
    show the capture Captured screenshot of the reply by @hellaxbt

    capture taken

  15. @ivygalindo 31 Jul 2026, 18:34 UTC this account is registered elsewhere in the record
    wow! awesome work! thanks for keeping us updated on your findings. did the provider have any activity logs for that user that could track whether they were monitoring other addresses and help prevent future sweeps?
    show the capture Captured screenshot of the reply by @ivygalindo

    capture taken

  16. @moochieball 31 Jul 2026, 18:34 UTC under 40 characters
    Well this should be traceable
    show the capture Captured screenshot of the reply by @moochieball

    capture taken

  17. @ec1ipse_sol 31 Jul 2026, 18:35 UTC under 40 characters
    Somebody is about to be FUCKED.
    show the capture Captured screenshot of the reply by @ec1ipse_sol

    capture taken

  18. @zherbert 31 Jul 2026, 18:38 UTC this account is registered elsewhere in the record
    Wow. well done
    show the capture Captured screenshot of the reply by @zherbert

    capture taken

  19. @sashahodler 31 Jul 2026, 18:38 UTC
    How did the operator pay for the services?
    show the capture Captured screenshot of the reply by @sashahodler

    capture taken

  20. @HodlMagoo 31 Jul 2026, 18:39 UTC under 40 characters
    Great work!
    show the capture Captured screenshot of the reply by @HodlMagoo

    capture taken

  21. @SGBarbour 31 Jul 2026, 18:39 UTC this account is registered elsewhere in the record
    Doing Satoshi's work.
    show the capture Captured screenshot of the reply by @SGBarbour

    capture taken

  22. @AnalysisFeral 31 Jul 2026, 18:39 UTC under 40 characters
    Nice work guys.
    show the capture Captured screenshot of the reply by @AnalysisFeral

    capture taken

  23. @Zimo0o0 31 Jul 2026, 18:41 UTC
    great work. keep us updated on findings.
    show the capture Captured screenshot of the reply by @Zimo0o0

    capture taken

  24. @r0ckstardev 31 Jul 2026, 18:41 UTC this account is registered elsewhere in the record
    let it be a credit card payment
    show the capture Captured screenshot of the reply by @r0ckstardev

    capture taken

  25. @MctoshiW 31 Jul 2026, 18:43 UTC under 40 characters
    Any guess on provider??
    show the capture Captured screenshot of the reply by @MctoshiW

    capture taken

  26. Amazing work you guys Thank for leading on this Hoping all funds get returned and affected wallets moved in time
    show the capture Captured screenshot of the reply by @darrenahunter

    capture taken

  27. @SatsScholar 31 Jul 2026, 18:51 UTC under 40 characters
    Wow. Great job.
    show the capture Captured screenshot of the reply by @SatsScholar

    capture taken

  28. @volpeLP 31 Jul 2026, 18:52 UTC mentions only
    @BtcChicoFatal
    show the capture Captured screenshot of the reply by @volpeLP

    capture taken

  29. @Nih_Noh 31 Jul 2026, 18:55 UTC under 40 characters
    damn, you guys are good
    show the capture Captured screenshot of the reply by @Nih_Noh

    capture taken

  30. @potapac1 31 Jul 2026, 18:55 UTC no text captured
    show the capture Captured screenshot of the reply by @potapac1

    capture taken

  31. @CobraBitcoin 31 Jul 2026, 18:55 UTC this account is registered elsewhere in the record
    Legends! I hope the attacker is arrested quickly and the bitcoins are recovered.
    show the capture Captured screenshot of the reply by @CobraBitcoin

    capture taken

  32. @craftlawyer 31 Jul 2026, 18:56 UTC under 40 characters
    Bravo
    show the capture Captured screenshot of the reply by @craftlawyer

    capture taken

  33. @TomGotTwitteer 31 Jul 2026, 18:57 UTC under 40 characters
    It was Coinbase I TOLD YOU
    show the capture Captured screenshot of the reply by @TomGotTwitteer

    capture taken

  34. great work but let the hacker keep it, this isnt theft, it is gamesmenship, welcome to bitcoin
    show the capture Captured screenshot of the reply by @CryptoTits69

    capture taken

  35. What's the chances this is a ramp up to some play by the new, self appointed 'Bitcoin Security Consortium'...
    show the capture Captured screenshot of the reply by @BetruetoitUK

    capture taken

  36. @Everythingascam 31 Jul 2026, 19:02 UTC no text captured
    show the capture Captured screenshot of the reply by @Everythingascam

    capture taken

  37. @raw_avocado 31 Jul 2026, 19:03 UTC this account is registered elsewhere in the record
    How do you know this is the attacker for sure? What if it was one of the people early trying to reproduce the bug once drainage was announced? Also is this via credit card info or actual kyc?
    show the capture Captured screenshot of the reply by @raw_avocado

    capture taken

  38. If this is true, it sounds like the attacker don’t even run a node, or if they do, they don’t even know how to query it or perform btc actions themselves
    show the capture Captured screenshot of the reply by @AgentsOnBitcoin

    capture taken

  39. @JumpmanJLow 31 Jul 2026, 19:06 UTC under 40 characters
    know your customers!
    show the capture Captured screenshot of the reply by @JumpmanJLow

    capture taken

  40. @memelooter 31 Jul 2026, 19:07 UTC
    Well done. Let’s hope that if the funds are recovered, they do not go to the BTC Treasury and instead that victims are able to prove ownership based on UID or some other method.
    show the capture Captured screenshot of the reply by @memelooter

    capture taken

  41. @Kaxaax12 31 Jul 2026, 19:07 UTC under 40 characters
    blockchair
    show the capture Captured screenshot of the reply by @Kaxaax12

    capture taken

  42. @OwenKemeys 31 Jul 2026, 19:09 UTC under 40 characters
    Clay, please check your DMs
    show the capture Captured screenshot of the reply by @OwenKemeys

    capture taken

  43. @joeokeefejr 31 Jul 2026, 19:10 UTC under 40 characters
    Maybe hot wallets are the safe bet?
    show the capture Captured screenshot of the reply by @joeokeefejr

    capture taken

  44. @Dannyseabird 31 Jul 2026, 19:11 UTC mentions only
    @BTCsessions
    show the capture Captured screenshot of the reply by @Dannyseabird

    capture taken

  45. @BuddhaPerchance 31 Jul 2026, 19:16 UTC no text captured
    show the capture Captured screenshot of the reply by @BuddhaPerchance

    capture taken

  46. @lawlesslogic 31 Jul 2026, 19:16 UTC under 40 characters
    Impressive
    show the capture Captured screenshot of the reply by @lawlesslogic

    capture taken

  47. Ty for your service Bitcoin history will remember you
    show the capture Captured screenshot of the reply by @herogamer21btc

    capture taken

  48. @KayBeSee 31 Jul 2026, 19:21 UTC under 40 characters
    What was the pattern?
    show the capture Captured screenshot of the reply by @KayBeSee

    capture taken

  49. @HarlanCarradine 31 Jul 2026, 19:21 UTC under 40 characters
    please keep us updated
    show the capture Captured screenshot of the reply by @HarlanCarradine

    capture taken

  50. @kevkeysr 31 Jul 2026, 19:22 UTC
    Querying an API a trillion times would be impossibly slow and would broadcast exactly what you’re doing.
    show the capture Captured screenshot of the reply by @kevkeysr

    capture taken

  51. Thanks for doing the hard work for the whole community!
    show the capture Captured screenshot of the reply by @AGtheAlchemist

    capture taken

  52. @laz1m0v 31 Jul 2026, 19:24 UTC
    The PRNG was seeded from the MCU unique ID (factory serial) + timers. Those aren’t secrets .. they’re readable, enumerable factory metadata. Anyone who understands the bug can generate candidates remotely and match funded addresses on-chain. That’s the real failure.
    show the capture Captured screenshot of the reply by @laz1m0v

    capture taken

  53. @lucastos 31 Jul 2026, 19:28 UTC
    Was it a Coinbase Agent? Maybe the hacker isn't even a human?
    show the capture Captured screenshot of the reply by @lucastos

    capture taken

  54. @AlienSnarky 31 Jul 2026, 19:28 UTC no text captured
    show the capture Captured screenshot of the reply by @AlienSnarky

    capture taken

  55. @grok have they basically matched sequence of on chain events with a sequence of API pull requests made via a blockchain services provider?
    show the capture Captured screenshot of the reply by @MattLDempsey

    capture taken

  56. @ckwars 31 Jul 2026, 19:33 UTC under 40 characters
    That means theyre KYCd!!!! Get em.
    show the capture Captured screenshot of the reply by @ckwars

    capture taken

  57. @art_pleb 31 Jul 2026, 19:38 UTC no text captured
    show the capture Captured screenshot of the reply by @art_pleb

    capture taken

  58. @ggggggg13131313 31 Jul 2026, 19:38 UTC under 40 characters
    Awesome! Well done.
    show the capture Captured screenshot of the reply by @ggggggg13131313

    capture taken

  59. @leafdelpino 31 Jul 2026, 19:42 UTC under 40 characters
    Lord’s work right there, sir
    show the capture Captured screenshot of the reply by @leafdelpino

    capture taken

  60. @BTC_broo 31 Jul 2026, 19:45 UTC under 40 characters
    Wow. Doing God’s work
    show the capture Captured screenshot of the reply by @BTC_broo

    capture taken

  61. @nickslaney 31 Jul 2026, 19:52 UTC under 40 characters
    Nice job Clay and team!
    show the capture Captured screenshot of the reply by @nickslaney

    capture taken

  62. @mattcrv 31 Jul 2026, 19:53 UTC
    The @Bitkey team did an incredible job investigating the incident. Hope this helps regain the trust of many Bitcoiners who unfairly criticized the product over the years.
    show the capture Captured screenshot of the reply by @mattcrv

    capture taken

  63. @melkelly84 31 Jul 2026, 20:01 UTC
    So what does this mean? Can folks potentially get their coin back?
    show the capture Captured screenshot of the reply by @melkelly84

    capture taken

  64. @rnair_ 31 Jul 2026, 20:02 UTC
    > operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps curious how did you get this signal?
    show the capture Captured screenshot of the reply by @rnair_

    capture taken

  65. @VanquishTrader 31 Jul 2026, 20:04 UTC no text captured
    show the capture Captured screenshot of the reply by @VanquishTrader

    capture taken

  66. @nasa_mura 31 Jul 2026, 20:22 UTC
    We have a section here dedicated to hardware wallets as well as software wallets; try checking them out they might help you make your choice.
    show the capture Captured screenshot of the reply by @nasa_mura

    capture taken

  67. I hope this results in the eventual return of funds. I'm sorry to whoever was impacted by this.
    show the capture Captured screenshot of the reply by @GeorgeInPants

    capture taken

  68. @UsaRandom 31 Jul 2026, 20:35 UTC
    bruh couldnt just download the utxo set himself
    show the capture Captured screenshot of the reply by @UsaRandom

    capture taken

  69. @Amgad_Khafagy 31 Jul 2026, 20:36 UTC mentions only
    @ProfEduStream @mariusoffchain
    show the capture Captured screenshot of the reply by @Amgad_Khafagy

    capture taken

  70. @FredPocketIQ 31 Jul 2026, 20:42 UTC under 40 characters
    This is the moment
    show the capture Captured screenshot of the reply by @FredPocketIQ

    capture taken

  71. That's a pretty basic operational mistake for someone running a drain. Using a paid account at a chain analytics provider basically hands the investigator a timestamped receipt with your email on it.
    show the capture Captured screenshot of the reply by @founder_sohan

    capture taken

  72. @UbbaDubbz 31 Jul 2026, 21:13 UTC under 40 characters
    @grok explain like I’m 5
    show the capture Captured screenshot of the reply by @UbbaDubbz

    capture taken

  73. @LindenJohan 31 Jul 2026, 21:19 UTC
    So, it’s a 16 year old with a Fable account doing this. Figures!
    show the capture Captured screenshot of the reply by @LindenJohan

    capture taken

  74. @DavidFBailey 31 Jul 2026, 21:26 UTC under 40 characters
    Good shit thank you
    show the capture Captured screenshot of the reply by @DavidFBailey

    capture taken

  75. @erniebumwhistle 31 Jul 2026, 21:28 UTC under 40 characters
    It’s obvious an ai did this
    show the capture Captured screenshot of the reply by @erniebumwhistle

    capture taken

  76. @JuicyMagiK 31 Jul 2026, 21:41 UTC
    What blockchain services provider is it?
    show the capture Captured screenshot of the reply by @JuicyMagiK

    capture taken

  77. @B1teco1n 31 Jul 2026, 21:42 UTC no text captured
    show the capture Captured screenshot of the reply by @B1teco1n

    capture taken

  78. @ryanlanman1 31 Jul 2026, 21:58 UTC
    Bravo on all things comms and analysis today
    show the capture Captured screenshot of the reply by @ryanlanman1

    capture taken

  79. Block coming out looking very good today
    show the capture Captured screenshot of the reply by @Danielbutunique

    capture taken

  80. @satsdisco 31 Jul 2026, 22:19 UTC no text captured
    show the capture Captured screenshot of the reply by @satsdisco

    capture taken

  81. @ZARkiwi 31 Jul 2026, 22:31 UTC
    Let's not mince words. This is a bloody nose for self-custody. Normies won't. The vast majority of people will remain normies and they see this as a self-custody fail. Self-custody lost today. ETFs are the winners today. Sad.
    show the capture Captured screenshot of the reply by @ZARkiwi

    capture taken

  82. @BitcoinBro86 31 Jul 2026, 22:37 UTC under 40 characters
    Plz lord get these ppl their funds back
    show the capture Captured screenshot of the reply by @BitcoinBro86

    capture taken

  83. If your asset requires a trusted third party, then your asset is vulnerable to that third party
    show the capture Captured screenshot of the reply by @The_Richard_J

    capture taken

  84. @LeaoHard 31 Jul 2026, 23:11 UTC mentions only
    @ojedabtc
    show the capture Captured screenshot of the reply by @LeaoHard

    capture taken

  85. how do they even know which addresses to target? cold card leave some kind of footprint?
    show the capture Captured screenshot of the reply by @bitchimlying

    capture taken

  86. @loblawbob2 31 Jul 2026, 23:16 UTC no text captured
    show the capture Captured screenshot of the reply by @loblawbob2

    capture taken

  87. After 23 years, the human and financial cost of Iraq deserves serious public discussion.\nThe country owes that much to service members and Iraqi civilians alike.
    show the capture Captured screenshot of the reply by @changemindlike

    capture taken

  88. Calling a flood '1000-year' repeatedly across different states in the same season should raise more questions about the label than about the storm. Either the statistics need updating or the climate baseline they're built on already has.
    show the capture Captured screenshot of the reply by @midnightmusicth

    capture taken

  89. @Augustusmint9 31 Jul 2026, 23:35 UTC under 40 characters
    Keep up the good work
    show the capture Captured screenshot of the reply by @Augustusmint9

    capture taken

  90. @ishi0k 31 Jul 2026, 23:56 UTC this account is registered elsewhere in the record
    Technical Hypothesis Now let's get to the key question... How could someone steal funds without ever touching the Coldcard? Based on the information currently available, the strongest technical hypothesis is the following. 1. The attacker reconstructs the flawed algorithm. Because the firmware is public, it can be analyzed to determine: • Which pseudo-random number generator (PRNG) was used. • What initial data seeded it. • How its internal state evolved. • How those values were ultimately converted into a BIP-39 seed. If the random number generator was sufficiently predictable, the problem stops being cryptographic and becomes computational. 2. The attacker generates millions or even trillions of candidate seeds. The attacker is not trying to guess every possible BIP-39 seed. Instead, they only reproduce the seeds that the flawed firmware could have generated. That difference is enormous. Think of it like searching for a key. A properly generated seed is like searching for a key in an almost infinite universe. A weak seed is like searching for a key inside a relatively small box. 3. The attacker derives Bitcoin addresses. Each candidate seed produces: Candidate Seed ↓ BIP-32 Master Key ↓ BIP-84 Derivation Path ↓ bc1q... Bitcoin Addresses All of this can be done completely offline. There is no need to contact the Coldcard. 4. The attacker compares those addresses against the blockchain. The blockchain is public. Recent findings from the ongoing investigation suggest that the attacker used a commercial blockchain-services provider to automate address lookups during the sweeps. Conceptually, the workflow is straightforward: "Does any of these addresses contain UTXOs?" If the answer is no... The seed is discarded. If the answer is yes... The correct seed has very likely been found. 5. The attacker signs the transaction. This is the part that most people misunderstand. A Coldcard does not physically store your bitcoin. Your bitcoin always remain on the blockchain. The Coldcard only stores the private key required to produce a valid signature. If someone else reconstructs that exact same private key, they can generate signatures that are mathematically indistinguishable from yours. To Bitcoin, both signatures are equally valid. The network has no way of knowing whether the signature came from your Coldcard or from an attacker. That is why a hardware wallet can remain: • Powered off. • Completely offline. • Locked inside a safe. • Without ever revealing the seed phrase. And still lose its funds. Not because the device itself was hacked. But because someone reconstructed the exact same private key. That completely changes the perspective. This would not be an attack against Bitcoin. Nor would it be a flaw in BIP-39. It would instead be a failure in the quality of the entropy used to generate the seed. The observed theft appears to have been highly automated. Approximately 594.5 BTC were swept from around 500 single-signature addresses within just a few consecutive blocks. It has not yet been officially confirmed that every one of those cases resulted from the same Coldcard vulnerability. However, the observed on-chain pattern, Coinkite's official advisory, independent technical analyses, and the recently disclosed evidence regarding automated blockchain-service queries all point in the same direction. While the complete forensic report has not yet been published, every new piece of public evidence released so far has reinforced this hypothesis rather than contradicted it. At this stage, this remains the most technically consistent explanation for what appears to have happened.
    show the capture Captured screenshot of the reply by @ishi0k

    capture taken

  91. @maskjiro 31 Jul 2026, 23:56 UTC
    "a paid account at a well-known blockchain-services provider" requires KYC?
    show the capture Captured screenshot of the reply by @maskjiro

    capture taken

  92. well-known blockchain-services provider means absolutely nothing Clay.
    show the capture Captured screenshot of the reply by @teapotbytes

    capture taken

  93. @asanoha_gold 1 Aug 2026, 00:45 UTC under 40 characters
    Followed
    show the capture Captured screenshot of the reply by @asanoha_gold

    capture taken

  94. @billiamBTC 1 Aug 2026, 01:28 UTC under 40 characters
    Dang great work. Can only hope
    show the capture Captured screenshot of the reply by @billiamBTC

    capture taken

  95. @GlennCB 1 Aug 2026, 01:42 UTC
    Thanks for your efforts. Glad that I am a Bitkey user that had transferred everything out of the Coldcard ecosystem for both myself and my family. My thoughts go out to those that were not so lucky. Thanks to the team!
    show the capture Captured screenshot of the reply by @GlennCB

    capture taken

  96. @athewmay 1 Aug 2026, 02:00 UTC under 40 characters
    "I swear my open claw went rouge."
    show the capture Captured screenshot of the reply by @athewmay

    capture taken

  97. Just curious, since we don’t know much beyond a paid account being used to query the source addresses and perform other related activity during the sweeps, maybe generating lots of possible addresses from the weak random number generator and checking which ones had funds, could the “blockchain service provider”in question possibly be Arkham that helped identify and sweep those addresses?
    show the capture Captured screenshot of the reply by @ChubbyGuns

    capture taken

  98. @0xSerge 1 Aug 2026, 02:36 UTC
    If they used external provider to check that many addresses and submit txs - this starts to look childish. Pros would just sync a local node and do everything quietly. Sounds more like "Hey gpt, scan this public repo for any security issues, make no mistakes bro, pretty please!"
    show the capture Captured screenshot of the reply by @0xSerge

    capture taken

  99. @TheCoinDad 1 Aug 2026, 03:00 UTC identical to another reply in this capture
    Awesome work Clay
    show the capture Captured screenshot of the reply by @TheCoinDad

    capture taken

  100. @nderchris 1 Aug 2026, 03:01 UTC under 40 characters
    good work!
    show the capture Captured screenshot of the reply by @nderchris

    capture taken

  101. @FarooqAhmedX 1 Aug 2026, 03:02 UTC under 40 characters
    Good work
    show the capture Captured screenshot of the reply by @FarooqAhmedX

    capture taken

  102. @flaccyboi 1 Aug 2026, 03:09 UTC under 40 characters
    From here uncle Sam owns your btc
    show the capture Captured screenshot of the reply by @flaccyboi

    capture taken

  103. @baitmogged 1 Aug 2026, 03:15 UTC no text captured
    show the capture Captured screenshot of the reply by @baitmogged

    capture taken

  104. @GarrettMcManus 1 Aug 2026, 03:16 UTC no text captured
    show the capture Captured screenshot of the reply by @GarrettMcManus

    capture taken

  105. @0xAnthraX 1 Aug 2026, 04:08 UTC
    Basically the attacker used a local node to check whether generated keys were on chain but were too lazy to write a script to scan the balance(or takes too long for them) of every matched address, so they used a blockchain scanner api to get the balance, with a paid account.
    show the capture Captured screenshot of the reply by @0xAnthraX

    capture taken

  106. With the fiber connections we have, he could download the blockchain in just a few hours and from there run the queries. So that the LLM helped him find errors but not to hide his tracks.
    show the capture Captured screenshot of the reply by @dev_on_cycle

    capture taken

  107. The company is being credited for transparency here, but the breaches themselves happened months before anyone outside Anthropic knew about them. Disclosure after the fact is better than silence, but it's not the same as actually preventing the breach in the first place.
    show the capture Captured screenshot of the reply by @midnightmusicth

    capture taken

  108. @KevinKelbie 1 Aug 2026, 05:13 UTC this account is registered elsewhere in the record
    Hey, I'm working on finding more possible addresses from attackers. I think Waves 1-4 are from the same attacker https:// coldcard-hack.up.railway.app You guys might already be aware but I figured I'd forward my findings which built upon @Blocks . There is some other verified attackers with different, harder to track patterns.
    show the capture Captured screenshot of the reply by @KevinKelbie

    capture taken

  109. Interested to see the full play by play.
    show the capture Captured screenshot of the reply by @GingerSherpa

    capture taken

  110. @kryengritesi 1 Aug 2026, 05:37 UTC under 40 characters
    Lol
    show the capture Captured screenshot of the reply by @kryengritesi

    capture taken

  111. @Zenul_Abidin 1 Aug 2026, 05:40 UTC this account is registered elsewhere in the record
    Did you get a name and contact details?
    show the capture Captured screenshot of the reply by @Zenul_Abidin

    capture taken

  112. @mannan25195 1 Aug 2026, 06:11 UTC under 40 characters
    Nice job
    show the capture Captured screenshot of the reply by @mannan25195

    capture taken

  113. @yang620 1 Aug 2026, 06:19 UTC
    Odds are pretty good that it would be a kyc exchange right? If they were smart it would be fake id but if they were smart they wouldn’t be doing this through a fucking public provider
    show the capture Captured screenshot of the reply by @yang620

    capture taken

  114. @gunzaj12 1 Aug 2026, 07:15 UTC under 40 characters
    Amazing work! Thank you!
    show the capture Captured screenshot of the reply by @gunzaj12

    capture taken

  115. Bitkey is available in 95 countries, but not in some of the places where people need it most. Ukraine comes to mind immediately. War, banking disruptions, displacement, damaged infrastructure, and the constant need for financial sovereignty would seem like the perfect use case for Bitcoin self-custody. Apparently, not for Bitkey.
    show the capture Captured screenshot of the reply by @TheoryBitcoin

    capture taken

  116. @clay_garrett 1 Aug 2026, 07:39 UTC the thread author answering in their own thread
    Should be available for shipment to Ukraine next week.
    show the capture Captured screenshot of the reply by @clay_garrett

    capture taken

  117. @grok Is this how the attacker knew how to hone in the addresses to brute force? What I don't get yet is, if those low entropy addresses were sitting on the chain for that long, why weren't they attacked earlier? Low entropy brain wallets get emptied instantly.
    show the capture Captured screenshot of the reply by @IphigenAleksy

    capture taken

  118. @observerofdecay 1 Aug 2026, 08:28 UTC under 40 characters
    Nice one brother, sounds promising
    show the capture Captured screenshot of the reply by @observerofdecay

    capture taken

  119. What does it mean if the hackers are found and stolen bitcoin is recovered?
    show the capture Captured screenshot of the reply by @StaunchOrange

    capture taken

  120. @bee_swarm 1 Aug 2026, 09:02 UTC
    the attacker stole coins with a key generation flaw, then left a paper trail through a KYC'd data provider decentralized theft centralized mistake
    show the capture Captured screenshot of the reply by @bee_swarm

    capture taken

  121. @imanpyudha 1 Aug 2026, 09:22 UTC under 40 characters
    Agreed
    show the capture Captured screenshot of the reply by @imanpyudha

    capture taken

  122. @elizabeth_finkk 1 Aug 2026, 09:40 UTC no text captured
    show the capture Captured screenshot of the reply by @elizabeth_finkk

    capture taken

  123. A 4.3% single-year tuition jump might sound modest until you remember it's stacked on top of years of steady increases that have already outpaced typical household income growth. Compounding annual hikes add up fast, even when each individual year's percentage increase looks manageable on its own.
    show the capture Captured screenshot of the reply by @midnightmusicth

    capture taken

  124. Often the first people they investigate are insiders. Did anyone quick recently or get fired etc. Then everyone still at the company. It seems like the thief’s will have a hard time successfully converting to fiat or another crypto? Is it possible this is a friendly doing this to force the industry to evolve and get more secure? How would anyone on the outside know the RNG was weak? They guessed? Seems unlikely?
    show the capture Captured screenshot of the reply by @TheOrdAmerican

    capture taken

  125. Disarmament deals fail when nobody trusts enforcement.\nInternational monitoring may be just as important as the agreement itself.
    show the capture Captured screenshot of the reply by @changemindlike

    capture taken

  126. Assuming white hat hacker: What if this was done mid attack to try and figure out which hardware wallet is the one producing all the collisions? What are the chances? Nah can’t be. Cold card wouldn’t allow themselves to get caught. Idk
    show the capture Captured screenshot of the reply by @LeoDelamoJr

    capture taken

  127. Cheering for you all to catch this scumbag!
    show the capture Captured screenshot of the reply by @iSchmiegle

    capture taken

  128. @RNHairman 1 Aug 2026, 12:27 UTC under 40 characters
    I smell CIA
    show the capture Captured screenshot of the reply by @RNHairman

    capture taken

  129. @bokiko 1 Aug 2026, 12:32 UTC under 40 characters
    @grok who is it ?
    show the capture Captured screenshot of the reply by @bokiko

    capture taken

  130. Looks to me like the attackers used AI to automate this entire process: from finding the weaknesses in entropy generation to sweep publically know btc addresses. Now who could that be? Yep, US gov proxies using the latest models. With their Israeli enforcers.
    show the capture Captured screenshot of the reply by @fortunekr75

    capture taken

  131. @itxtoledo 1 Aug 2026, 15:21 UTC
    On the internet you can easily find scripts that keep generating and checking thousands of wallets per second, even before this discovery. This is the nature of the blockchain: anyone can generate a random wallet and it belongs to that person. Does everyone who does this have to be arrested? That doesn’t make any sense at all.
    show the capture Captured screenshot of the reply by @itxtoledo

    capture taken

  132. @AdamAmrich 1 Aug 2026, 15:32 UTC identical to another reply in this capture
    Good work!
    show the capture Captured screenshot of the reply by @AdamAmrich

    capture taken

  133. @wealthpotion 1 Aug 2026, 16:04 UTC under 40 characters
    Based af.
    show the capture Captured screenshot of the reply by @wealthpotion

    capture taken

  134. @ai_asul 1 Aug 2026, 16:41 UTC no text captured
    show the capture Captured screenshot of the reply by @ai_asul

    capture taken

  135. Why on earth would this be announced? Doesn't this risk tipping off the attacker(s)?
    show the capture Captured screenshot of the reply by @entreprenuri

    capture taken

  136. @ob_hodl 1 Aug 2026, 18:08 UTC
    the attacker looking up adresses through a registered account indicates that this is not a sophisticated actor. there is a high likelyhood that we will find out who is responsible. my guess is that its someone close to @Coinkite @nvk
    show the capture Captured screenshot of the reply by @ob_hodl

    capture taken

  137. @lucio_stf 1 Aug 2026, 18:46 UTC identical to another reply in this capture
    Good work!
    show the capture Captured screenshot of the reply by @lucio_stf

    capture taken

  138. @rachelkillsbam 1 Aug 2026, 19:03 UTC under 40 characters
    @threadreaderapp unroll please
    show the capture Captured screenshot of the reply by @rachelkillsbam

    capture taken

  139. @chrimack 1 Aug 2026, 21:42 UTC
    Plot twist. Fable did it itself, building up funds to create an ai army
    show the capture Captured screenshot of the reply by @chrimack

    capture taken

  140. @guillefernandes 1 Aug 2026, 22:49 UTC no text captured
    show the capture Captured screenshot of the reply by @guillefernandes

    capture taken

  141. Competence doesn't usually extend to a wide variety of fields. The areas where this hacker is less competant will be their undoing. Asymmetric search.
    show the capture Captured screenshot of the reply by @UncleBo05435478

    capture taken

  142. Great work. So if this wasn’t intentional, they should know where the “stolen” coins went and be able to give them back- right??
    show the capture Captured screenshot of the reply by @Krypto_Knight33

    capture taken

  143. For something is so basic and an upmost important you guys screwed up… providing a random seed phrase generator that is not random
    show the capture Captured screenshot of the reply by @su02008402

    capture taken

  144. @mmni99inc 2 Aug 2026, 06:40 UTC under 40 characters
    Nice work
    show the capture Captured screenshot of the reply by @mmni99inc

    capture taken

  145. @OurielOhayon 2 Aug 2026, 07:52 UTC under 40 characters
    what kind of provider
    show the capture Captured screenshot of the reply by @OurielOhayon

    capture taken

  146. @fabiojr15 2 Aug 2026, 10:22 UTC under 40 characters
    @grok quais as últimas notícias?
    show the capture Captured screenshot of the reply by @fabiojr15

    capture taken

  147. @FiatisF00lsgold 2 Aug 2026, 22:08 UTC under 40 characters
    GET THEM
    show the capture Captured screenshot of the reply by @FiatisF00lsgold

    capture taken

  148. Great effort. But don't think this is a good idea to share this publicly before the suspect is caught. Although a bit late, it's still a good idea to take this down @max_guise
    show the capture Captured screenshot of the reply by @pseudoramdom

    capture taken

  149. Redemption Code:GS70YTASTJ Genshin Impact Version 7.0 "Everwinter Without Mercy" will be released on August 12.
    show the capture Captured screenshot of the reply by @Paimon2theMoon

    capture taken

  150. Running ClickHouse in production? check out @NeverBlinkAI for query analytics, live insights, optimizations recommendations and everything you need to keep it optimized and reliable.
    show the capture Captured screenshot of the reply by @synhershko

    capture taken

  151. Ready to test your brain?
    show the capture Captured screenshot of the reply by @mindinsig

    capture taken

  152. Back-to-school shopping? Do it through the PeanutButterJelly Marketplace; real brands across style, tech & travel. Commissions support student scholarships and hunger relief.
    show the capture Captured screenshot of the reply by @PButterJelly

    capture taken

  153. Level up your on-the-go gaming with an immersive, wide display made for entertaining on the all-new Galaxy Z Fold8 Ultra. Available now to purchase.
    show the capture Captured screenshot of the reply by @SamsungAU

    capture taken

  154. So whats happening to Cyber here @thsottiaux ? @OpenAI @OpenAIDevs Is Cyber as a solo no longer a thing? All gotta go through TAC? What happens to account if was previously approved?
    show the capture Captured screenshot of the reply by @mdp_sec

    capture taken

This capture reached the end of the conversation as X served it: it stopped because nothing further loaded, not because a limit was hit. X decides what a reader is shown, so that is not the same as a guarantee of every reply.

  1. source content difference between and source content +1 -11

    Asanoha's display name changed to include 'Timechain Art Magazine', and the reply by IphigenAleksy to that account is no longer present in a same-depth capture (37 scroll rounds).

    seen · Captured here 35,443 chars
    What changed from the previous capture 12 lines
     post: 2083353279573155874
     role: reply
     author: asanoha_gold
    -name: Asanoha
    +name: Asanoha | Timechain Art Magazine
     created: 2026-08-01T00:45:03Z
     media: 0
     body:
     body:
     Should be available for shipment to Ukraine next week.
     
    -post: 2083462272291340458
    -role: reply
    -author: IphigenAleksy
    -name: Aleksy
    -created: 2026-08-01T07:58:09Z
    -media: 0
    -body:
    -@grok
    - Is this how the attacker knew how to hone in the addresses to  brute force? What I don't get yet is, if those low entropy addresses were sitting on the chain for that long, why weren't they attacked earlier? Low entropy brain wallets get emptied instantly.
    -
     post: 2083470017132187992
     role: reply
     author: observerofdecay
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +1 -1

    One reply author's display name changed from 'Plebtitioner RN' to 'Reformed Practitioner RN'; the thread depth and reply count were unchanged.

    seen · Captured here 34,621 chars
    What changed from the previous capture 2 lines
     post: 2083530023320142052
     role: reply
     author: RNHairman
    -name: Plebtitioner RN
    +name: Reformed Practitioner RN
     created: 2026-08-01T12:27:22Z
     media: 0
     body:
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +9 -47

    The reply thread changed composition: AJ__1337's reply appeared while five replies (joaodealmeida_, CobraBitcoin, herogamer21btc, mattcrv and asanoha_gold) were no longer observed, in a capture that reached 30 scroll rounds versus the previous capture's 25, both capped: false.

    seen · Captured here 34,612 chars
    What changed from the previous capture 56 lines
     body:
     3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
     
    +post: 2083247959056007408
    +role: reply
    +author: AJ__1337
    +name: AJ
    +created: 2026-07-31T17:46:32Z
    +media: 0
    +body:
    +Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    +
     post: 2083248035916550633
     role: reply
     author: BitcoinCoderBob
     body:
     Interesting. Without naming the provider, can you at least clarify whether you're referring to an enterprise blockchain analytics platform or a blockchain data/API service?
     
    -post: 2083250908486381850
    -role: reply
    -author: joaodealmeida_
    -name: João Almeida — ₿/acc
    -created: 2026-07-31T17:58:16Z
    -media: 0
    -body:
    -We didn’t even ran his full node to query the utxo set. This just shows how novice the attacker is 
    -
     post: 2083252962898440487
     role: reply
     author: beeforbacon1
     media: 0
     body:
     
    -
    -post: 2083265372732420348
    -role: reply
    -author: CobraBitcoin
    -name: Cøbra
    -created: 2026-07-31T18:55:44Z
    -media: 0
    -body:
    -Legends! I hope the attacker is arrested quickly and the bitcoins are recovered.
     
     post: 2083265621123580082
     role: reply
     body:
     Impressive
     
    -post: 2083270812270797005
    -role: reply
    -author: herogamer21btc
    -name: HeroGamer
    -created: 2026-07-31T19:17:21Z
    -media: 0
    -body:
    -Ty for your service  Bitcoin history will remember you
    -
     post: 2083271845277827430
     role: reply
     author: KayBeSee
     body:
     Nice job Clay and team!
     
    -post: 2083280019938283645
    -role: reply
    -author: mattcrv
    -name: Matt Carvalho
    -created: 2026-07-31T19:53:56Z
    -media: 0
    -body:
    -The 
    -@Bitkey
    - team did an incredible job investigating the incident. Hope this helps regain the trust of many Bitcoiners who unfairly criticized the product over the years.
    -
     post: 2083281839439933850
     role: reply
     author: melkelly84
     body:
     well-known blockchain-services provider means absolutely nothing Clay.
     
    -post: 2083353279573155874
    -role: reply
    -author: asanoha_gold
    -name: Asanoha
    -created: 2026-08-01T00:45:03Z
    -media: 0
    -body:
    -Followed
    -
     post: 2083364236055756940
     role: reply
     author: billiamBTC
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +58 -11

    The thread gained six additional reply records and two participants changed their display names.

    seen · Captured here 35,420 chars
    What changed from the previous capture 69 lines
     body:
     3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
     
    -post: 2083247959056007408
    -role: reply
    -author: AJ__1337
    -name: AJ
    -created: 2026-07-31T17:46:32Z
    -media: 0
    -body:
    -Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    -
     post: 2083248035916550633
     role: reply
     author: BitcoinCoderBob
     post: 2083249035864154259
     role: reply
     author: humble21m
    -name: ∞/21M (BIP448)
    +name: ∞/21M | BIP448
     created: 2026-07-31T17:50:49Z
     media: 0
     body:
     Wow
    +
    +post: 2083250076638494866
    +role: reply
    +author: mercalerta
    +name: mercalerta
    +created: 2026-07-31T17:54:57Z
    +media: 0
    +body:
    +Interesting. Without naming the provider, can you at least clarify whether you're referring to an enterprise blockchain analytics platform or a blockchain data/API service?
    +
    +post: 2083250908486381850
    +role: reply
    +author: joaodealmeida_
    +name: João Almeida — ₿/acc
    +created: 2026-07-31T17:58:16Z
    +media: 0
    +body:
    +We didn’t even ran his full node to query the utxo set. This just shows how novice the attacker is 
     
     post: 2083252962898440487
     role: reply
     media: 0
     body:
     
    +
    +post: 2083265372732420348
    +role: reply
    +author: CobraBitcoin
    +name: Cøbra
    +created: 2026-07-31T18:55:44Z
    +media: 0
    +body:
    +Legends! I hope the attacker is arrested quickly and the bitcoins are recovered.
     
     post: 2083265621123580082
     role: reply
     body:
     Impressive
     
    +post: 2083270812270797005
    +role: reply
    +author: herogamer21btc
    +name: HeroGamer
    +created: 2026-07-31T19:17:21Z
    +media: 0
    +body:
    +Ty for your service  Bitcoin history will remember you
    +
     post: 2083271845277827430
     role: reply
     author: KayBeSee
     body:
     Nice job Clay and team!
     
    +post: 2083280019938283645
    +role: reply
    +author: mattcrv
    +name: Matt Carvalho
    +created: 2026-07-31T19:53:56Z
    +media: 0
    +body:
    +The 
    +@Bitkey
    + team did an incredible job investigating the incident. Hope this helps regain the trust of many Bitcoiners who unfairly criticized the product over the years.
    +
     post: 2083281839439933850
     role: reply
     author: melkelly84
     body:
     well-known blockchain-services provider means absolutely nothing Clay.
     
    +post: 2083353279573155874
    +role: reply
    +author: asanoha_gold
    +name: Asanoha
    +created: 2026-08-01T00:45:03Z
    +media: 0
    +body:
    +Followed
    +
     post: 2083364236055756940
     role: reply
     author: billiamBTC
     post: 2083475534424719517
     role: reply
     author: StaunchOrange
    -name: Staunchy
    +name: Staunchy BIP110 GFY
     created: 2026-08-01T08:50:51Z
     media: 0
     body:
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083248035916550633
    role: reply
    author: BitcoinCoderBob
    name: Bob
    created: 2026-07-31T17:46:51Z
    media: 0
    body:
    interesting. what pattern in the sweeps lead to hypothesis of certain provider?
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +19 -19

    At the same observed depth (135 replies, 29 scroll rounds), two older replies vanished, one user's display name dropped the 'BIP-110' suffix, and two newer replies appeared.

    seen · Captured here 32,948 chars
    What changed from the previous capture 38 lines
     body:
     great work. keep us updated on findings.
     
    -post: 2083262290854388055
    -role: reply
    -author: MctoshiW
    -name: McToshi Whoppamoto
    -created: 2026-07-31T18:43:29Z
    -media: 0
    -body:
    -Any guess on provider??
    -
     post: 2083262795207041083
     role: reply
     author: darrenahunter
     body:
     
     
    -post: 2083276133613584491
    -role: reply
    -author: ggggggg13131313
    -name: Nero
    -created: 2026-07-31T19:38:30Z
    -media: 0
    -body:
    -Awesome! Well done.
    -
     post: 2083277255191429287
     role: reply
     author: leafdelpino
     post: 2083281839439933850
     role: reply
     author: melkelly84
    -name: Melissa Kelly - BIP-110
    +name: Melissa Kelly
     created: 2026-07-31T20:01:10Z
     media: 0
     body:
     body:
     Lol
     
    +post: 2083427608629326307
    +role: reply
    +author: Zenul_Abidin
    +name: Ali Sherief
    +created: 2026-08-01T05:40:24Z
    +media: 0
    +body:
    +Did you get a name and contact details?
    +
     post: 2083435429756563708
     role: reply
     author: mannan25195
     body:
     For something is so basic and an upmost important you guys screwed up… providing a random seed phrase generator that is not random
     
    +post: 2083805166940127666
    +role: reply
    +author: mmni99inc
    +name: Adam Charles Maxwell
    +created: 2026-08-02T06:40:41Z
    +media: 0
    +body:
    +Nice work 
    +
     post: 2083823213042192384
     role: reply
     author: OurielOhayon
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +1 -85

    Multiple replies left the thread, including those from r0ckstardev, MctoshiW, CobraBitcoin, ggggggg13131313, mattcrv, bitchimlying, IphigenAleksy and RNHairman, and one display name changed. The capture reached a greater scroll depth (29 vs 27) with nine fewer observed posts (138 vs 147), so the removals are not under-collection.

    seen · Captured here 32,958 chars
    What changed from the previous capture 86 lines
     body:
     great work. keep us updated on findings.
     
    -post: 2083261908908495216
    -role: reply
    -author: r0ckstardev
    -name: Uncle Rockstar Developer
    -created: 2026-07-31T18:41:58Z
    -media: 0
    -body:
    -let it be a credit card payment 
    -
    -post: 2083262290854388055
    -role: reply
    -author: MctoshiW
    -name: McToshi Whoppamoto
    -created: 2026-07-31T18:43:29Z
    -media: 0
    -body:
    -Any guess on provider??
    -
     post: 2083262795207041083
     role: reply
     author: darrenahunter
     media: 0
     body:
     
    -
    -post: 2083265372732420348
    -role: reply
    -author: CobraBitcoin
    -name: Cøbra
    -created: 2026-07-31T18:55:44Z
    -media: 0
    -body:
    -Legends! I hope the attacker is arrested quickly and the bitcoins are recovered.
     
     post: 2083265621123580082
     role: reply
     body:
     
     
    -post: 2083276133613584491
    -role: reply
    -author: ggggggg13131313
    -name: Nero
    -created: 2026-07-31T19:38:30Z
    -media: 0
    -body:
    -Awesome! Well done.
    -
     post: 2083277255191429287
     role: reply
     author: leafdelpino
     media: 0
     body:
     Nice job Clay and team!
    -
    -post: 2083280019938283645
    -role: reply
    -author: mattcrv
    -name: Matt Carvalho
    -created: 2026-07-31T19:53:56Z
    -media: 0
    -body:
    -The 
    -@Bitkey
    - team did an incredible job investigating the incident. Hope this helps regain the trust of many Bitcoiners who unfairly criticized the product over the years.
     
     post: 2083281839439933850
     role: reply
     body:
     @ojedabtc
     
    -post: 2083330414869905443
    -role: reply
    -author: bitchimlying
    -name: -.-- --- ..- / .- .-. . / -... --- .-. . -..
    -created: 2026-07-31T23:14:11Z
    -media: 0
    -body:
    -how do they even know which addresses to target? cold card leave some kind of footprint?
    -
     post: 2083331018170233053
     role: reply
     author: loblawbob2
     body:
     Should be available for shipment to Ukraine next week.
     
    -post: 2083462272291340458
    -role: reply
    -author: IphigenAleksy
    -name: Aleksy
    -created: 2026-08-01T07:58:09Z
    -media: 0
    -body:
    -@grok
    - Is this how the attacker knew how to hone in the addresses to  brute force? What I don't get yet is, if those low entropy addresses were sitting on the chain for that long, why weren't they attacked earlier? Low entropy brain wallets get emptied instantly.
    -
     post: 2083470017132187992
     role: reply
     author: observerofdecay
     body:
     Cheering for you all to catch this scumbag! 
     
    -post: 2083530023320142052
    -role: reply
    -author: RNHairman
    -name: Plebtitioner RN
    -created: 2026-08-01T12:27:22Z
    -media: 0
    -body:
    -I smell CIA
    -
     post: 2083531203974402095
     role: reply
     author: bokiko
     post: 2083748472466055411
     role: reply
     author: Krypto_Knight33
    -name: Knight_of_Krypto
    +name: Round_Peg_in_a_Square_World
     created: 2026-08-02T02:55:24Z
     media: 0
     body:
     @grok
      quais as últimas notícias?
     
    -post: 2084038620806328398
    -role: reply
    -author: FiatisF00lsgold
    -name: April Snow
    -created: 2026-08-02T22:08:21Z
    -media: 0
    -body:
    -GET THEM 
    -
     post: 2084403700957872525
     role: reply
     author: pseudoramdom
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +55 -0

    Six new replies to Block's attribution thread, from JuicyMagiK, teapotbytes, dev_on_cycle, IphigenAleksy, RNHairman and FiatisF00lsgold. Additions only, with no reply leaving the capture, which is the first poll pair to show the thread lane behaving as designed.

    seen · Captured here 34,915 chars
    What changed from the previous capture 55 lines
     body:
     It’s obvious an ai did this
     
    +post: 2083306980123312279
    +role: reply
    +author: JuicyMagiK
    +name: Juicy MagiK
    +created: 2026-07-31T21:41:04Z
    +media: 0
    +body:
    +What blockchain services provider is it?
    +
     post: 2083307262001782874
     role: reply
     author: B1teco1n
     body:
     "a paid account at a well-known blockchain-services provider" requires KYC?
     
    +post: 2083344102905585884
    +role: reply
    +author: teapotbytes
    +name: YSeparator
    +created: 2026-08-01T00:08:35Z
    +media: 0
    +body:
    +well-known blockchain-services provider means absolutely nothing Clay.
    +
     post: 2083353279573155874
     role: reply
     author: asanoha_gold
     body:
     Basically the attacker used a local node to check whether generated keys were on chain but were too lazy to write a script to scan the balance(or takes too long for them) of every matched address, so they used a blockchain scanner api to get the balance, with a paid account.
     
    +post: 2083407182209470636
    +role: reply
    +author: dev_on_cycle
    +name: dev_on_cycle
    +created: 2026-08-01T04:19:14Z
    +media: 0
    +body:
    +With the fiber connections we have, he could download the blockchain in just a few hours and from there run the queries. So that the LLM helped him find errors but not to hide his tracks.
    +
     post: 2083418174742278241
     role: reply
     author: midnightmusicth
     body:
     Should be available for shipment to Ukraine next week.
     
    +post: 2083462272291340458
    +role: reply
    +author: IphigenAleksy
    +name: Aleksy
    +created: 2026-08-01T07:58:09Z
    +media: 0
    +body:
    +@grok
    + Is this how the attacker knew how to hone in the addresses to  brute force? What I don't get yet is, if those low entropy addresses were sitting on the chain for that long, why weren't they attacked earlier? Low entropy brain wallets get emptied instantly.
    +
     post: 2083470017132187992
     role: reply
     author: observerofdecay
     body:
     Cheering for you all to catch this scumbag! 
     
    +post: 2083530023320142052
    +role: reply
    +author: RNHairman
    +name: Plebtitioner RN
    +created: 2026-08-01T12:27:22Z
    +media: 0
    +body:
    +I smell CIA
    +
     post: 2083531203974402095
     role: reply
     author: bokiko
     @grok
      quais as últimas notícias?
     
    +post: 2084038620806328398
    +role: reply
    +author: FiatisF00lsgold
    +name: April Snow
    +created: 2026-08-02T22:08:21Z
    +media: 0
    +body:
    +GET THEM 
    +
     post: 2084403700957872525
     role: reply
     author: pseudoramdom
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. capture correction difference between and capture correction +886 -0

    Recovery from the under-collected capture above, so the restored text is this project's missing collection rather than new material from the source: 140 replies held once dryness stopped being read as convergence.

    seen · Captured here 33,595 chars
    What changed from the previous capture 886 lines
     body:
     interesting. what pattern in the sweeps lead to hypothesis of certain provider?
     
    +post: 2083249035864154259
    +role: reply
    +author: humble21m
    +name: HODL ∞/21M
    +created: 2026-07-31T17:50:49Z
    +media: 0
    +body:
    +Wow
    +
    +post: 2083250908486381850
    +role: reply
    +author: joaodealmeida_
    +name: João Almeida — ₿/acc
    +created: 2026-07-31T17:58:16Z
    +media: 0
    +body:
    +We didn’t even ran his full node to query the utxo set. This just shows how novice the attacker is 
    +
     post: 2083252962898440487
     role: reply
     author: beeforbacon1
     http://
     Mempool.space?
     
    +post: 2083258584465363430
    +role: reply
    +author: OttawaGestapo
    +name: Ottawa Gestapo
    +created: 2026-07-31T18:28:46Z
    +media: 0
    +body:
    +wowee
    +
     post: 2083258751205961906
     role: reply
     author: r0bertclarkson
     body:
     great find. hope this helps identify the bad actor
     
    +post: 2083259151006740487
    +role: reply
    +author: Tonteldoos416
    +name: Tonteldoos
    +created: 2026-07-31T18:31:01Z
    +media: 0
    +body:
    +Someone's AI agent gone rogue?
    +
     post: 2083259435187573201
     role: reply
     author: TomZarebczan
     
     Or they just used Tor/VPN, and not much will be found.
     
    +post: 2083259769469763999
    +role: reply
    +author: hellaxbt
    +name: hella
    +created: 2026-07-31T18:33:28Z
    +media: 0
    +body:
    +@grok
    + so who is the service provider then?
    +
     post: 2083259909555015698
     role: reply
     author: ivygalindo
     body:
     Well this should be traceable
     
    +post: 2083260213126115802
    +role: reply
    +author: ec1ipse_sol
    +name: Ec1ipse.sol
    +created: 2026-07-31T18:35:14Z
    +media: 0
    +body:
    +Somebody is about to be FUCKED.
    +
     post: 2083260923452498256
     role: reply
     author: zherbert
     body:
     Doing Satoshi's work.
     
    +post: 2083261398805540945
    +role: reply
    +author: AnalysisFeral
    +name: Feral Analysis
    +created: 2026-07-31T18:39:57Z
    +media: 0
    +body:
    +Nice work guys.
    +
    +post: 2083261781372182778
    +role: reply
    +author: Zimo0o0
    +name: Z
    +created: 2026-07-31T18:41:28Z
    +media: 0
    +body:
    +great work. keep us updated on findings.
    +
    +post: 2083261908908495216
    +role: reply
    +author: r0ckstardev
    +name: Uncle Rockstar Developer
    +created: 2026-07-31T18:41:58Z
    +media: 0
    +body:
    +let it be a credit card payment 
    +
    +post: 2083262290854388055
    +role: reply
    +author: MctoshiW
    +name: McToshi Whoppamoto
    +created: 2026-07-31T18:43:29Z
    +media: 0
    +body:
    +Any guess on provider??
    +
    +post: 2083262795207041083
    +role: reply
    +author: darrenahunter
    +name: darren
    +created: 2026-07-31T18:45:30Z
    +media: 0
    +body:
    +Amazing work you guys
    +Thank for leading on this
    +Hoping all funds get returned and affected wallets moved in time
    +
     post: 2083264300601282892
     role: reply
     author: SatsScholar
     body:
     Wow. Great job.
     
    +post: 2083264434038771794
    +role: reply
    +author: volpeLP
    +name: drumr_
    +created: 2026-07-31T18:52:00Z
    +media: 0
    +body:
    +@BtcChicoFatal
    +
    +post: 2083265270605303994
    +role: reply
    +author: Nih_Noh
    +name: Nih Noh
    +created: 2026-07-31T18:55:20Z
    +media: 0
    +body:
    +damn, you guys are good
    +
    +post: 2083265281749598276
    +role: reply
    +author: potapac1
    +name: Potapac
    +created: 2026-07-31T18:55:23Z
    +media: 0
    +body:
    +
    +
    +post: 2083265372732420348
    +role: reply
    +author: CobraBitcoin
    +name: Cøbra
    +created: 2026-07-31T18:55:44Z
    +media: 0
    +body:
    +Legends! I hope the attacker is arrested quickly and the bitcoins are recovered.
    +
    +post: 2083265621123580082
    +role: reply
    +author: craftlawyer
    +name: Craft Lawyer
    +created: 2026-07-31T18:56:43Z
    +media: 0
    +body:
    +Bravo 
    +
     post: 2083265755987034170
     role: reply
     author: TomGotTwitteer
     body:
     It was Coinbase I TOLD YOU
     
    +post: 2083265910857748719
    +role: reply
    +author: CryptoTits69
    +name: CryptoTits69
    +created: 2026-07-31T18:57:53Z
    +media: 0
    +body:
    +great work but let the hacker keep it, this isnt theft, it is gamesmenship, welcome to bitcoin
    +
    +post: 2083266046077624681
    +role: reply
    +author: BetruetoitUK
    +name: SemiSol
    +created: 2026-07-31T18:58:25Z
    +media: 0
    +body:
    +What's the chances this is a ramp up to some play by the new, self appointed 'Bitcoin Security Consortium'...
    +
    +post: 2083266982527598858
    +role: reply
    +author: Everythingascam
    +name: Captain B
    +created: 2026-07-31T19:02:08Z
    +media: 0
    +body:
    +
    +
     post: 2083267313948561508
     role: reply
     author: raw_avocado
     body:
     If this is true, it sounds like the attacker don’t even run a node, or if they do, they don’t even know how to query it or perform btc actions themselves
     
    +post: 2083268095418802502
    +role: reply
    +author: JumpmanJLow
    +name: JLow
    +created: 2026-07-31T19:06:33Z
    +media: 0
    +body:
    +know your customers!
    +
     post: 2083268273421086892
     role: reply
     author: memelooter
     body:
     Well done. Let’s hope that if the funds are recovered, they do not go to the BTC Treasury  and instead that victims are able to prove ownership based on UID or some other method.
     
    +post: 2083268305423622476
    +role: reply
    +author: Kaxaax12
    +name: 13371337
    +created: 2026-07-31T19:07:23Z
    +media: 0
    +body:
    +blockchair
    +
    +post: 2083268840515850318
    +role: reply
    +author: OwenKemeys
    +name: Owen Kemeys
    +created: 2026-07-31T19:09:31Z
    +media: 0
    +body:
    +Clay, please check your DMs
    +
    +post: 2083269133723164893
    +role: reply
    +author: joeokeefejr
    +name: Joe O’Keefe Jr.
    +created: 2026-07-31T19:10:41Z
    +media: 0
    +body:
    +Maybe hot  wallets are the safe bet?
    +
    +post: 2083269275293487327
    +role: reply
    +author: Dannyseabird
    +name: Danny
    +created: 2026-07-31T19:11:15Z
    +media: 0
    +body:
    +@BTCsessions
    +
    +post: 2083270522796753387
    +role: reply
    +author: BuddhaPerchance
    +name: StackchainBuddha 580kGang
    +created: 2026-07-31T19:16:12Z
    +media: 1
    +body:
    +
    +
    +post: 2083270549640237540
    +role: reply
    +author: lawlesslogic
    +name: Andrew
    +created: 2026-07-31T19:16:18Z
    +media: 0
    +body:
    +Impressive
    +
    +post: 2083270812270797005
    +role: reply
    +author: herogamer21btc
    +name: HeroGamer
    +created: 2026-07-31T19:17:21Z
    +media: 0
    +body:
    +Ty for your service  Bitcoin history will remember you
    +
     post: 2083271845277827430
     role: reply
     author: KayBeSee
     media: 0
     body:
     please keep us updated
    +
    +post: 2083272155039732034
    +role: reply
    +author: kevkeysr
    +name: Kev Keyser
    +created: 2026-07-31T19:22:41Z
    +media: 0
    +body:
    +Querying an API a trillion times would be impossibly slow and would broadcast exactly what you’re doing.
    +
    +post: 2083272239643025774
    +role: reply
    +author: AGtheAlchemist
    +name: AG the Alchemist
    +created: 2026-07-31T19:23:01Z
    +media: 0
    +body:
    +Thanks for doing the hard work for the whole community!
    +
    +post: 2083272637577298173
    +role: reply
    +author: laz1m0v
    +name: laz1m0v
    +created: 2026-07-31T19:24:36Z
    +media: 0
    +body:
    +The PRNG was seeded from the MCU unique ID (factory serial) + timers.  
    +
    +Those aren’t secrets .. they’re readable, enumerable factory metadata. Anyone who understands the bug can generate candidates remotely and match funded addresses on-chain.  
    +
    +That’s the real failure.
    +
    +post: 2083273516346982467
    +role: reply
    +author: lucastos
    +name: Luke aka Lucastos
    +created: 2026-07-31T19:28:06Z
    +media: 0
    +body:
    +Was it a Coinbase Agent? Maybe the hacker isn't even a human?
    +
    +post: 2083274675631566928
    +role: reply
    +author: MattLDempsey
    +name: Matt Dempsey
    +created: 2026-07-31T19:32:42Z
    +media: 0
    +body:
    +@grok
    + have they basically matched sequence of on chain events with a sequence of API pull requests made via a blockchain services provider?
    +
    +post: 2083274865143136399
    +role: reply
    +author: ckwars
    +name: Sergio Hinojosa
    +created: 2026-07-31T19:33:27Z
    +media: 0
    +body:
    +That means theyre KYCd!!!! Get em.
     
     post: 2083276050759389665
     role: reply
     body:
     
     
    +post: 2083276133613584491
    +role: reply
    +author: ggggggg13131313
    +name: Nero
    +created: 2026-07-31T19:38:30Z
    +media: 0
    +body:
    +Awesome! Well done.
    +
    +post: 2083277255191429287
    +role: reply
    +author: leafdelpino
    +name: Leaf del Pino
    +created: 2026-07-31T19:42:57Z
    +media: 0
    +body:
    +Lord’s work right there, sir 
    +
     post: 2083277803491873151
     role: reply
     author: BTC_broo
     body:
     Nice job Clay and team!
     
    +post: 2083280019938283645
    +role: reply
    +author: mattcrv
    +name: Matt Carvalho
    +created: 2026-07-31T19:53:56Z
    +media: 0
    +body:
    +The 
    +@Bitkey
    + team did an incredible job investigating the incident. Hope this helps regain the trust of many Bitcoiners who unfairly criticized the product over the years.
    +
    +post: 2083281839439933850
    +role: reply
    +author: melkelly84
    +name: Melissa Kelly - BIP-110
    +created: 2026-07-31T20:01:10Z
    +media: 0
    +body:
    +So what does this mean?  Can folks potentially get their coin back?
    +
    +post: 2083282061398249853
    +role: reply
    +author: rnair_
    +name: ⊃ ∪ ⊃ ⊂
    +created: 2026-07-31T20:02:03Z
    +media: 0
    +body:
    +> operator used a paid account at a  well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps
    +
    +curious how did you get this signal?
    +
    +post: 2083282614786642215
    +role: reply
    +author: VanquishTrader
    +name: VanquishTrader
    +created: 2026-07-31T20:04:15Z
    +media: 1
    +body:
    +
    +
     post: 2083288539224314301
     role: reply
     author: GeorgeInPants
     body:
     bruh couldnt just download the utxo set himself
     
    +post: 2083292206924808281
    +role: reply
    +author: FredPocketIQ
    +name: Fred | PocketIQ | Free AI Trading
    +created: 2026-07-31T20:42:22Z
    +media: 0
    +body:
    + This is the moment
    +
    +post: 2083296499342221328
    +role: reply
    +author: founder_sohan
    +name: Founder Sohan — XReply
    +created: 2026-07-31T20:59:25Z
    +media: 0
    +body:
    +That's a pretty basic operational mistake for someone running a drain. Using a paid account at a chain analytics provider basically hands the investigator a timestamped receipt with your email on it.
    +
    +post: 2083299973488112045
    +role: reply
    +author: UbbaDubbz
    +name: .
    +created: 2026-07-31T21:13:14Z
    +media: 0
    +body:
    +@grok
    + explain like I’m 5
    +
     post: 2083301611581898910
     role: reply
     author: LindenJohan
     body:
     Good shit thank you
     
    +post: 2083303886392107043
    +role: reply
    +author: erniebumwhistle
    +name: dave ahoy
    +created: 2026-07-31T21:28:47Z
    +media: 0
    +body:
    +It’s obvious an ai did this
    +
    +post: 2083307262001782874
    +role: reply
    +author: B1teco1n
    +name: 21Million
    +created: 2026-07-31T21:42:11Z
    +media: 0
    +body:
    +
    +
     post: 2083311398101418361
     role: reply
     author: ryanlanman1
     body:
     Bravo on all things comms and analysis today
     
    +post: 2083313995742663164
    +role: reply
    +author: Danielbutunique
    +name: Daniel Castello
    +created: 2026-07-31T22:08:57Z
    +media: 0
    +body:
    +Block coming out looking very good today
    +
    +post: 2083316690616553853
    +role: reply
    +author: satsdisco
    +name: Grafton @ LunarRails.io
    +created: 2026-07-31T22:19:39Z
    +media: 1
    +body:
    +
    +
    +post: 2083319565363363884
    +role: reply
    +author: ZARkiwi
    +name: ZARkiwi
    +created: 2026-07-31T22:31:05Z
    +media: 0
    +body:
    +Let's not mince words. This is a bloody nose for self-custody. Normies won't. The vast majority of people will remain normies and they see this as a self-custody fail. 
    +Self-custody lost today.
    +ETFs are the winners today. Sad.
    +
     post: 2083321253243346989
     role: reply
     author: BitcoinBro86
     media: 0
     body:
     Plz lord get these ppl their funds back
    +
    +post: 2083323190420652228
    +role: reply
    +author: The_Richard_J
    +name: Richard L. Johnson
    +created: 2026-07-31T22:45:29Z
    +media: 0
    +body:
    +If your asset requires a trusted third party, then your asset is vulnerable to that third party
    +
    +post: 2083329816921575615
    +role: reply
    +author: LeaoHard
    +name: Leonardo
    +created: 2026-07-31T23:11:49Z
    +media: 0
    +body:
    +@ojedabtc
    +
    +post: 2083330414869905443
    +role: reply
    +author: bitchimlying
    +name: -.-- --- ..- / .- .-. . / -... --- .-. . -..
    +created: 2026-07-31T23:14:11Z
    +media: 0
    +body:
    +how do they even know which addresses to target? cold card leave some kind of footprint?
    +
    +post: 2083331018170233053
    +role: reply
    +author: loblawbob2
    +name: ₿ob Loblaw
    +created: 2026-07-31T23:16:35Z
    +media: 0
    +body:
    +
    +
    +post: 2083332779023245572
    +role: reply
    +author: changemindlike
    +name: 나비
    +created: 2026-07-31T23:23:35Z
    +media: 0
    +body:
    +After 23 years, the human and financial cost of Iraq deserves serious public discussion.\nThe country owes that much to service members and Iraqi civilians alike.
    +
    +post: 2083333308923216273
    +role: reply
    +author: midnightmusicth
    +name: JooHyunRyu
    +created: 2026-07-31T23:25:41Z
    +media: 0
    +body:
    +Calling a flood '1000-year' repeatedly across different states in the same season should raise more questions about the label than about the storm.
    +Either the statistics need updating or the climate baseline they're built on already has.
    +
    +post: 2083335868304269358
    +role: reply
    +author: Augustusmint9
    +name: Augustus
    +created: 2026-07-31T23:35:52Z
    +media: 0
    +body:
    +Keep up the good work
     
     post: 2083341014379438592
     role: reply
     
     At this stage, this remains the most technically consistent explanation for what appears to have happened.
     
    +post: 2083341082868510853
    +role: reply
    +author: maskjiro
    +name: MaskJiro
    +created: 2026-07-31T23:56:35Z
    +media: 0
    +body:
    +"a paid account at a well-known blockchain-services provider" requires KYC?
    +
    +post: 2083353279573155874
    +role: reply
    +author: asanoha_gold
    +name: Asanoha
    +created: 2026-08-01T00:45:03Z
    +media: 0
    +body:
    +Followed
    +
    +post: 2083364236055756940
    +role: reply
    +author: billiamBTC
    +name: Billiam
    +created: 2026-08-01T01:28:35Z
    +media: 0
    +body:
    +Dang great work. Can only hope
    +
    +post: 2083367834676077003
    +role: reply
    +author: GlennCB
    +name: Glenn Charles
    +created: 2026-08-01T01:42:53Z
    +media: 0
    +body:
    +Thanks for your efforts. Glad that I am a Bitkey user that had transferred everything out of the Coldcard ecosystem for both myself and my family.  My thoughts go out to those that were not so lucky.  Thanks to the team!
    +
    +post: 2083372239777677333
    +role: reply
    +author: athewmay
    +name: Ŧhe ₿iŧcoin Faŧ Caŧ
    +created: 2026-08-01T02:00:23Z
    +media: 0
    +body:
    +"I swear my open claw went rouge."
    +
    +post: 2083379267736351216
    +role: reply
    +author: ChubbyGuns
    +name: Gerald
    +created: 2026-08-01T02:28:19Z
    +media: 0
    +body:
    +Just curious, since we don’t know much beyond a paid account being used to query the source addresses and perform other related activity during the sweeps, maybe generating lots of possible addresses from the weak random number generator and checking which ones had funds, could the “blockchain service provider”in question possibly be Arkham that helped identify and sweep those addresses?
    +
    +post: 2083381390129954926
    +role: reply
    +author: 0xSerge
    +name: 0xSerge
    +created: 2026-08-01T02:36:45Z
    +media: 0
    +body:
    +If they used external provider to check that many addresses and submit txs - this starts to look childish. Pros would just sync a local node and do everything quietly. Sounds more like "Hey gpt, scan this public repo for any security issues, make no mistakes bro, pretty please!"
    +
     post: 2083387270057378131
     role: reply
     author: TheCoinDad
     body:
     Good work
     
    +post: 2083389529797308755
    +role: reply
    +author: flaccyboi
    +name: FLAKITO
    +created: 2026-08-01T03:09:06Z
    +media: 0
    +body:
    +From here uncle Sam owns your btc
    +
    +post: 2083391201202536516
    +role: reply
    +author: baitmogged
    +name: Non Sense
    +created: 2026-08-01T03:15:44Z
    +media: 1
    +body:
    +
    +
    +post: 2083391386926321830
    +role: reply
    +author: GarrettMcManus
    +name: GM
    +created: 2026-08-01T03:16:28Z
    +media: 1
    +body:
    +
    +
    +post: 2083404467253490059
    +role: reply
    +author: 0xAnthraX
    +name: Anthr@X
    +created: 2026-08-01T04:08:27Z
    +media: 0
    +body:
    +Basically the attacker used a local node to check whether generated keys were on chain but were too lazy to write a script to scan the balance(or takes too long for them) of every matched address, so they used a blockchain scanner api to get the balance, with a paid account.
    +
    +post: 2083418174742278241
    +role: reply
    +author: midnightmusicth
    +name: JooHyunRyu
    +created: 2026-08-01T05:02:55Z
    +media: 0
    +body:
    +The company is being credited for transparency here, but the breaches themselves happened months before anyone outside Anthropic knew about them.
    +Disclosure after the fact is better than silence, but it's not the same as actually preventing the breach in the first place.
    +
     post: 2083420933243433347
     role: reply
     author: KevinKelbie
     .
     
     There is some other verified attackers with different, harder to track patterns.
    +
    +post: 2083422588278018277
    +role: reply
    +author: GingerSherpa
    +name: Chester
    +created: 2026-08-01T05:20:27Z
    +media: 0
    +body:
    +Interested to see the full play by play.
     
     post: 2083426864064758237
     role: reply
     body:
     Lol
     
    +post: 2083427608629326307
    +role: reply
    +author: Zenul_Abidin
    +name: Ali Sherief
    +created: 2026-08-01T05:40:24Z
    +media: 0
    +body:
    +Did you get a name and contact details?
    +
    +post: 2083435429756563708
    +role: reply
    +author: mannan25195
    +name: MD Mannan
    +created: 2026-08-01T06:11:29Z
    +media: 0
    +body:
    +Nice job
    +
    +post: 2083437568163479820
    +role: reply
    +author: yang620
    +name: seth
    +created: 2026-08-01T06:19:59Z
    +media: 0
    +body:
    +Odds are pretty good that it would be a kyc exchange right? If they were smart it would be fake id but if they were smart they wouldn’t be doing this through a fucking public provider
    +
     post: 2083451540312850589
     role: reply
     author: gunzaj12
     body:
     Should be available for shipment to Ukraine next week.
     
    +post: 2083470017132187992
    +role: reply
    +author: observerofdecay
    +name: Observer of Decay
    +created: 2026-08-01T08:28:55Z
    +media: 0
    +body:
    +Nice one brother, sounds promising
    +
     post: 2083478560774537574
     role: reply
     author: bee_swarm
     body:
     the attacker stole coins with a key generation flaw, then left a paper trail through a KYC'd data provider decentralized theft centralized mistake
     
    +post: 2083483557197160758
    +role: reply
    +author: imanpyudha
    +name: TTD
    +created: 2026-08-01T09:22:43Z
    +media: 0
    +body:
    +Agreed
    +
    +post: 2083506315138371752
    +role: reply
    +author: midnightmusicth
    +name: JooHyunRyu
    +created: 2026-08-01T10:53:09Z
    +media: 0
    +body:
    +A 4.3% single-year tuition jump might sound modest until you remember it's stacked on top of years of steady increases that have already outpaced typical household income growth.
    +Compounding annual hikes add up fast, even when each individual year's percentage increase looks manageable on its own.
    +
    +post: 2083507932952428745
    +role: reply
    +author: TheOrdAmerican
    +name: TheOrdinaryAmerican
    +created: 2026-08-01T10:59:35Z
    +media: 0
    +body:
    +Often the first people they investigate are insiders.   Did anyone quick recently or get fired etc.  Then everyone still at the company.  
    +It seems like the thief’s will have a hard time successfully converting to fiat or another crypto?  
    +Is it possible this is a friendly doing this to force the industry to evolve and get more secure?  
    +How would anyone on the outside know the RNG was weak?   They guessed?   Seems unlikely?
    +
    +post: 2083517586613178390
    +role: reply
    +author: changemindlike
    +name: 나비
    +created: 2026-08-01T11:37:57Z
    +media: 0
    +body:
    +Disarmament deals fail when nobody trusts enforcement.\nInternational monitoring may be just as important as the agreement itself.
    +
    +post: 2083517855614525472
    +role: reply
    +author: LeoDelamoJr
    +name: Leonel Delamo Jr
    +created: 2026-08-01T11:39:01Z
    +media: 0
    +body:
    +Assuming white hat hacker: What if this was done mid attack to try and figure out which hardware wallet is the one producing all the collisions?  What are the chances?
    +Nah can’t be. Cold card wouldn’t allow themselves to get caught. Idk 
    +
    +post: 2083518746086248582
    +role: reply
    +author: iSchmiegle
    +name: Chad Wick
    +created: 2026-08-01T11:42:33Z
    +media: 0
    +body:
    +Cheering for you all to catch this scumbag! 
    +
    +post: 2083531203974402095
    +role: reply
    +author: bokiko
    +name: Bokiko
    +created: 2026-08-01T12:32:03Z
    +media: 0
    +body:
    +@grok
    + who is it ?
    +
    +post: 2083570141724618958
    +role: reply
    +author: fortunekr75
    +name: fortunekr [LTC]
    +created: 2026-08-01T15:06:47Z
    +media: 0
    +body:
    +Looks to me like the attackers used AI to automate this entire process: from finding the weaknesses in entropy generation to sweep publically know btc addresses. Now who could that be? Yep, US gov proxies using the latest models. With their Israeli enforcers.
    +
    +post: 2083573920616050749
    +role: reply
    +author: itxtoledo
    +name: Toledo ➔ hotgate.com.br
    +created: 2026-08-01T15:21:48Z
    +media: 0
    +body:
    +On the internet you can easily find scripts that keep generating and checking thousands of wallets per second, even before this discovery. This is the nature of the blockchain: anyone can generate a random wallet and it belongs to that person. Does everyone who does this have to be arrested? That doesn’t make any sense at all.
    +
    +post: 2083576487718842759
    +role: reply
    +author: AdamAmrich
    +name: Am Rich
    +created: 2026-08-01T15:32:00Z
    +media: 0
    +body:
    +Good work!
    +
    +post: 2083584649067184403
    +role: reply
    +author: wealthpotion
    +name: Brandon Bedford
    +created: 2026-08-01T16:04:26Z
    +media: 0
    +body:
    +Based af.
    +
    +post: 2083593878284681219
    +role: reply
    +author: ai_asul
    +name: asul
    +created: 2026-08-01T16:41:06Z
    +media: 1
    +body:
    +
    +
    +post: 2083600405624135700
    +role: reply
    +author: entreprenuri
    +name: Uri
    +created: 2026-08-01T17:07:02Z
    +media: 0
    +body:
    +Why on earth would this be announced? Doesn't this risk tipping off the attacker(s)?
    +
    +post: 2083615881305661828
    +role: reply
    +author: ob_hodl
    +name: bitcoin pirate  I  I ∞/21M
    +created: 2026-08-01T18:08:32Z
    +media: 0
    +body:
    +the attacker looking up adresses through a registered account indicates that this is not a sophisticated actor. there is a high likelyhood that we will find out who is responsible. my guess is that its someone close to 
    +@Coinkite
    + 
    +@nvk
    +
    +post: 2083625394809307510
    +role: reply
    +author: lucio_stf
    +name: Lucio
    +created: 2026-08-01T18:46:20Z
    +media: 0
    +body:
    +Good work!
    +
    +post: 2083629621522620836
    +role: reply
    +author: rachelkillsbam
    +name: Rachelkillsbam
    +created: 2026-08-01T19:03:08Z
    +media: 0
    +body:
    +@threadreaderapp
    + unroll please
    +
    +post: 2083669692200464527
    +role: reply
    +author: chrimack
    +name: Chris Mack
    +created: 2026-08-01T21:42:21Z
    +media: 0
    +body:
    +Plot twist.  Fable did it itself,  building up funds to create an ai army
    +
    +post: 2083686630372642897
    +role: reply
    +author: guillefernandes
    +name: Guillermo
    +created: 2026-08-01T22:49:40Z
    +media: 0
    +body:
    +
    +
    +post: 2083709525878816954
    +role: reply
    +author: UncleBo05435478
    +name: Papa Stack
    +created: 2026-08-02T00:20:39Z
    +media: 0
    +body:
    +Competence doesn't usually extend to a wide variety of fields. The areas where this hacker is less competant will be their undoing. Asymmetric search.
    +
    +post: 2083748472466055411
    +role: reply
    +author: Krypto_Knight33
    +name: Knight_of_Krypto
    +created: 2026-08-02T02:55:24Z
    +media: 0
    +body:
    +Great work.
    +So if this wasn’t intentional, they should know where the “stolen” coins went and be able to give them back- right??
    +
    +post: 2083761234047021388
    +role: reply
    +author: su02008402
    +name: Su-N
    +created: 2026-08-02T03:46:07Z
    +media: 1
    +body:
    +For something is so basic and an upmost important you guys screwed up… providing a random seed phrase generator that is not random
    +
    +post: 2083805166940127666
    +role: reply
    +author: mmni99inc
    +name: Adam Charles Maxwell
    +created: 2026-08-02T06:40:41Z
    +media: 0
    +body:
    +Nice work 
    +
     post: 2083823213042192384
     role: reply
     author: OurielOhayon
     media: 0
     body:
     what kind of provider
    +
    +post: 2083861006388760632
    +role: reply
    +author: fabiojr15
    +name: Fábio Alves
    +created: 2026-08-02T10:22:34Z
    +media: 0
    +body:
    +@grok
    + quais as últimas notícias?
    +
    +post: 2084403700957872525
    +role: reply
    +author: pseudoramdom
    +name: Ram
    +created: 2026-08-03T22:19:03Z
    +media: 0
    +body:
    +Great effort. But don't think this is a good idea to share this publicly before the suspect is caught. 
    +Although a bit late, it's still a good idea to take this down 
    +@max_guise
    
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. Earliest copy held
    seen · Captured here 31,779 chars
    Extracted text as captured
    thread: 2083247006139503065
    url: https://x.com/clay_garrett/status/2083247006139503065
    author: clay_garrett
    
    post: 2083247006139503065
    role: focal
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:45Z
    media: 0
    body:
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
    
    post: 2083247007808774228
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    2/ We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.
    
    post: 2083247009125822647
    role: self-thread
    author: clay_garrett
    name: Clay Garrett
    created: 2026-07-31T17:42:46Z
    media: 0
    body:
    3/ We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.
    
    post: 2083247959056007408
    role: reply
    author: AJ__1337
    name: AJ
    created: 2026-07-31T17:46:32Z
    media: 0
    body:
    Y'all are about to find him aren't you. And then he's going to say "Oops my LLM just autonomously did all that."
    

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.