1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
1/ Block’s engineering and security team found another set of transactions that could be a part of the Coldcard drain. We’re still working to vet these completely, but given the situation, we feel it’s important to share early.