Crazy indeed, but tbh the circulating theory of an inside jo...

npub14j7wc366rf8efqvnnm8m68pazy04kkj8fgu6uqumh3eqlhfst0kqrngtpf
hex
a359fa5d3a4f40b6e562403862eb0fc047c3810cec493307893a984c6ba60bb1nevent
nevent1qqs2xk06t5ay7s9ku43yqwrzav8uq37rsyxwcjfnq7yn4xzvdwnqhvgprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs2e08vgadp5nu5sxfeanaars73z86mtfr55wdwqwdmcus0m5c9hmq54jkqgKind-1 (TextNote)
Crazy indeed, but tbh the circulating theory of an inside job doesn't really make sense to me and seems overblown. I dunno, but...
They'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation.
I totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown.
nostr:nevent1qqsgy3avvjmtalecqv800akfvtjgqeufwsc5qwfufv7pj0jt45uwkrgpz9mhxue69uhkummnw3ezuamfdejj7q3qcf3zeytdnwgwzz5pk2ax0vvmmlzad03xcft4d50ejrfhsh8pxcdsxpqqqqqqz5zet0p
Raw JSON
{
"kind": 1,
"id": "a359fa5d3a4f40b6e562403862eb0fc047c3810cec493307893a984c6ba60bb1",
"pubkey": "acbcec475a1a4f9481939ecfbd1c3d111f5b5a474a39ae039bbc720fdd305bec",
"created_at": 1785841442,
"tags": [
[
"p",
"c2622c916d9b90e10a81b2ba67b19bdfc5d6be26c25756d1f990d3785ce1361b",
"wss://relay.bitcoinpark.com/"
],
[
"q",
"8247ac64b6beff38030ef7f6c962e4806789743140393c4b3c193e4bad38eb0d",
"wss://nostr.wine/",
"c2622c916d9b90e10a81b2ba67b19bdfc5d6be26c25756d1f990d3785ce1361b"
],
[
"zap",
"acbcec475a1a4f9481939ecfbd1c3d111f5b5a474a39ae039bbc720fdd305bec",
"wss://haven.d11n.net/",
"1.0"
],
[
"client",
"Amethyst"
]
],
"content": "Crazy indeed, but tbh the circulating theory of an inside job doesn't really make sense to me and seems overblown. I dunno, but...\n\nThey'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation. \n\nI totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown. \n\nnostr:nevent1qqsgy3avvjmtalecqv800akfvtjgqeufwsc5qwfufv7pj0jt45uwkrgpz9mhxue69uhkummnw3ezuamfdejj7q3qcf3zeytdnwgwzz5pk2ax0vvmmlzad03xcft4d50ejrfhsh8pxcdsxpqqqqqqz5zet0p",
"sig": "53541b6c39a80e6ee8933a26d5779cbef160ecdd1c6eafeb81f76549fb655e8e7772637339389fbb84c2848d079fb13279dd7126d3dc1c2ba9ce16a22045b680"
}