Crazy indeed, but tbh the circulating theory of an inside jo...

Dennis

npub14j7wc366rf8efqvnnm8m68pazy04kkj8fgu6uqumh3eqlhfst0kqrngtpf

hex

a359fa5d3a4f40b6e562403862eb0fc047c3810cec493307893a984c6ba60bb1

nevent

nevent1qqs2xk06t5ay7s9ku43yqwrzav8uq37rsyxwcjfnq7yn4xzvdwnqhvgprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgs2e08vgadp5nu5sxfeanaars73z86mtfr55wdwqwdmcus0m5c9hmq54jkqg

Kind-1 (TextNote)

2026-08-04T11:04:02Z

Crazy indeed, but tbh the circulating theory of an inside job doesn't really make sense to me and seems overblown. I dunno, but...

They'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation.

I totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown.

nostr:nevent1qqsgy3avvjmtalecqv800akfvtjgqeufwsc5qwfufv7pj0jt45uwkrgpz9mhxue69uhkummnw3ezuamfdejj7q3qcf3zeytdnwgwzz5pk2ax0vvmmlzad03xcft4d50ejrfhsh8pxcdsxpqqqqqqz5zet0p

原始 JSON

{
  "kind": 1,
  "id": "a359fa5d3a4f40b6e562403862eb0fc047c3810cec493307893a984c6ba60bb1",
  "pubkey": "acbcec475a1a4f9481939ecfbd1c3d111f5b5a474a39ae039bbc720fdd305bec",
  "created_at": 1785841442,
  "tags": [
    [
      "p",
      "c2622c916d9b90e10a81b2ba67b19bdfc5d6be26c25756d1f990d3785ce1361b",
      "wss://relay.bitcoinpark.com/"
    ],
    [
      "q",
      "8247ac64b6beff38030ef7f6c962e4806789743140393c4b3c193e4bad38eb0d",
      "wss://nostr.wine/",
      "c2622c916d9b90e10a81b2ba67b19bdfc5d6be26c25756d1f990d3785ce1361b"
    ],
    [
      "zap",
      "acbcec475a1a4f9481939ecfbd1c3d111f5b5a474a39ae039bbc720fdd305bec",
      "wss://haven.d11n.net/",
      "1.0"
    ],
    [
      "client",
      "Amethyst"
    ]
  ],
  "content": "Crazy indeed, but tbh the circulating theory of an inside job doesn't really make sense to me and seems overblown. I dunno, but...\n\nThey'd have accepted the risk for this to come up via external review and vulnerability reports before they could harvest a substantial amount. This would have destroyed the companies reputation similar to what we see now. There's also a the risk for an attacker to grab the funds before they get to collect them. Both scenarios seem way more likely then CoinKite or an employee sitting and waiting for five years — especially as there where multiple reports of individual incidents over these years, each asking for further investigation. \n\nI totally get why people are upset and wouldn't rule this out entirely, yet it seems far more unlikely to me. The more likely scenario imho is that they were too arrogant to look into the reports, giving the attacker the time to proceed slow and steady. Then, last week the attacker might have lost exclusivity on the insight and someone else joined the drain, forcing one of the hackers to go full blown. \n\nnostr:nevent1qqsgy3avvjmtalecqv800akfvtjgqeufwsc5qwfufv7pj0jt45uwkrgpz9mhxue69uhkummnw3ezuamfdejj7q3qcf3zeytdnwgwzz5pk2ax0vvmmlzad03xcft4d50ejrfhsh8pxcdsxpqqqqqqz5zet0p",
  "sig": "53541b6c39a80e6ee8933a26d5779cbef160ecdd1c6eafeb81f76549fb655e8e7772637339389fbb84c2848d079fb13279dd7126d3dc1c2ba9ce16a22045b680"
}