Jrakibi 2084947141202768295
jrakibi-2084947141202768295
- Author
- @jrakibi
- Organisation
- independent
- Evidence role
- scam-report
- Posted
- 5 Aug 2026, 10:18 UTC
- Capture status
- capture held
jrakibi warning that a repository which gained many stars in 24 hours, and claims to reproduce the vulnerable COLDCARD RNG, pulls a dependency that downloads and runs an infostealer searching for seeds, private keys and passwords. A specific and actionable secondary-attack report: the bait is reproduction of this defect, so the target is exactly the people investigating it. The repository is not named or linked here. The malicious behaviour is the reporter's LLM-assisted finding and is not verified by this archive.
This post is registered as evidence and has a locally held capture. The original remains the canonical publication. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.