News linked to both this project and an event.
According to CoinDesk, since the Coldcard hardware wallet vulnerability incident erupted on July 30, the wallet address associated with the hackers (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has received multiple Bitcoin transfers accompanied by text messages. The wallet currently holds approximately $36 million in stolen assets, and confirmed losses from this incident have exceeded $100 million. The aforementioned information was written on-chain via Bitcoin's OP_RETURN function and permanently stored on the blockchain. The content covers victims' pleas for compensation (such as "You stole, please return some," "Return 80% of my 5 BTC"), solicitations for money laundering services ("I launder BTC, taking a 10% commission," with Telegram contact information included), and even fundraising requests completely unrelated to the incident, varying in nature.
According to Decrypt, an anonymous cryptocurrency whale filed a lawsuit against Coinbase this week in the U.S. District Court for the Northern District of California, accusing the exchange of refusing to return over $55 million worth of DAI stablecoins stolen in a phishing attack in 2024. The plaintiff claims to have engaged multiple on-chain investigation firms to trace the funds, ultimately identifying that the stolen assets flowed into a Coinbase account. Coinbase confirmed in December 2024 that it had frozen the relevant assets but refused to return them, citing the need for a court order. As of today—more than a year and a half after the incident—the victim has still not recovered the assets and has therefore turned to litigation. The attack was carried out by hackers using the “Inferno Drainer” tool to spoof the DeFi Saver login page; after the victim inadvertently interacted with the fake page, their wallet was fully compromised by the attackers.