

Garry
109 posts









This is actually a textbook example of how AML/KYC works at most licensed operators, not the "shady casino" behavior people are reading it as I work in anti-fraud/payments at an online casino myself. A few things worth understanding: Platforms can't freeze funds on a third-party claim alone anyone could accuse anyone of anything and weaponize that to lock random users out of their own money. Requiring a signed message, an affidavit, and a clear evidence trail is exactly the kind of threshold that protects both the platform and legitimate users from that abuse. "We do KYC/AML" doesn't mean every single transaction gets manually reviewed in real time. Most operators run risk-based KYC verification gets triggered by specific flags, not by default on every deposit. On the deposit side specifically, even a $10M deposit might not trigger KYC on its own, because incoming funds are revenue for the platform there's little incentive to slow that down. The real scrutiny almost always shows up on the withdrawal side. What actually matters here isn't whether the bar for freezing exists it's how fast a platform moves once real evidence is in hand. Duel offering an exception without a police report is more than plenty of platforms would do. Fund freezes are the visible part. The part that actually leads somewhere is what happens next pulling KYC documentation and video verification on whoever deposited those funds. That's the step worth watching @Duelcomcasino @intangiblecoins @korraflow

Hi, Duel team here. We cannot simply freeze a user's funds because a third party claims it is stolen. Anyone can claim anything about someone else's balance. For example, I could swap my BTC for your ETH, claim you robbed me, and get your funds frozen... HOWEVER, I am happy to make a one time exception in this case, because I have sympathy for the Coldcard victims. If the victim is able to sign a message from an address of the "hack," sign an affidavit stating they were hacked, and show the clear trail of evidence leading to Duel, I will temporarily freeze the funds without a police or court order. You have to understand the reason this policy exists, we require SOME sort of official confirmation that an actual theft occured (so confirmation from law enforcement of any kind usually), otherwise anyone can claim stuff about their own balance or a counterparty or a third party they don't even know and get accounts frozen. It would be extremely anti-privacy, anti-crypto, and anti-bitcoin to freeze a balance because someone in support chat asked us to. I am hoping the crypto crowd of all people will understand why we try to preserve sanctity of on-site balances. But as noted, just this once, an exception is open. The alleged victim can send me the above details in DM and I'll get it done. Terrible situation and I have huge sympathy for scam victims but again we have to protect our users and abide by the law, balances on Duel are extremely sacred and it takes a fairly high threshold for us to seize them (essentially we have to be legally obliged to).












We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below. We are now tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across 7 attacker addresses. Updates to our analysis from yesterday 👇

Coldcard didn't just lose $38M , It lost closer to $70M (~1,050 BTC) 594 BTC gone. That's the number everyone's reporting. I traced the known wallets holding the stolen funds. Combined balance right now: ~1,050 BTC (~$66.7M), sitting completely untouched, zero outflows Nearly double what's in the headlines Wallets tracked: bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 - moved 562 BTC internally bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r - 562 BTC bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 - 398.5 BTC bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q - 89.6 BTC Watching these addresses. Will update if anything moves 👀


JUST IN: Coldcard, one of the best-known Bitcoin hardware wallets, warns users to move funds following a $38M $BTC theft. The issue affects seeds created on Coldcard Mk3 firmware from version 4.0.1 onward, as well as some older Mk4, Mk5 and Q firmware. Separately, researchers tracked a 594.48 BTC ($38M) theft, with no confirmed link to the Coldcard flaw.





We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett 1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks 960,183-960,191. That preceded the hardware-wallet vendor's public advisory by ~30 hours. Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output. That looks like an automated tool spending keys it already held, not owners moving funds. Victims: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44 — consistent with multi-path key scanning. Proceeds consolidated within minutes and have NOT moved since: - bc1qq85v2c9...cu9r — 562.02 BTC - bc1qx76cae2...fhe3 — 398.48 BTC - bc1q8jy96fe...tp3q — 89.62 BTC - bc1qnk4zh9q...fecp0 — 32.45 BTC (unmoved)

