😱A BTC holder just dodged a #
Coldcard# MK4 theft, moved his stack to a CEX… and got completely wiped in under 12 hours. $750k in #
BTC# gone. Reason? Google account owned + Google Authenticator cloud sync left on.
This is NOT a one-off. Most Google compromises aren’t brute force — they’re phishing + credential stuffing. The usual plays:
1. Fake Google login pages tricking you into handing over the password
2. Malicious browser extensions / cracked software silently yoinking cookies & creds
3. Weak password reuse → massive credential stuffing
4. Recovery email or phone number taken over → instant password reset.
🛡️GoPlus security playbook so you don’t get rekt:
1️⃣Google account → hardware key or Passkey on. Regularly audit devices, third-party access & recovery options. Password alone is a single point of failure.
2️⃣Cloud backup → keep Google Authenticator cloud sync OFF by default. Store recovery keys offline. Never let email + password + 2FA share the same trust chain.
3️⃣Exchange accounts → dedicated email only. Enable withdrawal address whitelist + cooldown period. Kill API withdrawal perms. Watch for abnormal logins like a hawk.
A very close friend of mine, coldcard MK4
User, after 6 years of suggesting Bitcoin to him, finally allocated and went pretty hard in 2025. 3/4 of a million dollars
Moved ALL to a very well known and solid Australian exchange
Less then 12 hours later, it was withdrawn
ALL gone
もっと見る