Garry

109 posts

Garry

Garry

@elxhick

AML officer / web3 researcher

onchain Katılım Temmuz 2026
72 Takip Edilen38 Takipçiler
Sabitlenmiş Tweet
Garry
Garry@elxhick·
BitMart moved $9M+ to other exchanges days before announcing shutdown 🧵 Jul 21-25: multiple 6-7 fig transfers from BitMart hot wallets to OKX/Binance/Bitget Jul 24: CEO fired, not consulted @50Nent Jul 26: "orderly wind-down announced" @BitMartExchange
Garry tweet media
English
3
2
9
4.3K
Garry
Garry@elxhick·
@intangiblecoins @korraflow you really think whoever made this deposit passed KYC with their own real ID? come on, once the police report confirms it, they'll just end up finding a mule who got paid $100-200 to pass KYC and take the fall
English
0
0
1
159
Alex Thorn
Alex Thorn@intangiblecoins·
thanks to @korraflow for working with me and identifying their depositor’s identity. it looks like funds left their platform before they were able to freeze them but they do have ID of the depositor. when the victim’s police report info arrives, they should be able to ID this one attacker unfortunately, these funds are not part of the large wave 1, 2, and 3 waves identified by @glxyresearch there are now smaller operators and copycats out here attacking remaining coldcard seeds
English
2
3
70
3.6K
Alex Thorn
Alex Thorn@intangiblecoins·
outrageous behavior by some in this world a nearly 30 BTC coldcard victim had 17 BTC peeled and sent over @THORChain to ETH, then deposited into @Duelcomcasino both the victim and a research emailed all known addresses for @Duelcomcasino and asked for freeze, provided all info on the txs and deposits 229.72497255 ETH ($445k), downstream from the victim's ~30 BTC coldcard hack, was deposited by the hacker into their sketchy offshore casino duel's response to the victim was for him to have the police contact them, despite the fact that their AML policies claim they perform KYC and adhere to all relevant laws this is an outrageous response. it's well after midnight in most of the western world. no police report is coming until at least Monday. these shady people are refusing to freeze funds that have been forensically proven to emanate from a live cyber incident. if they do not freeze the funds, they are complicit in theft. they were notified minutes after deposits were made. if duel doesn't freeze this money, they will face substantial legal action duel's x account is suspended so I am tagging people we could find associated with them (team, dealers, others) let these people know that they need to do the right thing @korraflow @atrois7 @MiaMalkova
English
58
72
767
81K
Garry
Garry@elxhick·
I get your position, but crypto and iGaming are adjacent industries, not identical ones and what @korraflow is saying actually checks out. I see swap-sourced deposits every single day in this line of work, and freezing on that alone basically never happens From my own experience in iGaming anti-fraud, actually freezing a deposit is genuinely rare it takes a real trigger, not just "funds passed through a swapper." Worth looking at this from the platform's side too, if they froze every deposit that touched a bridge or swap service
English
0
0
0
27
FixxTheMoney
FixxTheMoney@FixxTheMoneyy·
What is the connection that @intangiblecoins is making that the funds came from a victim/hackers wallet? Has no evidence of this been shown to you yet? Alex isn’t just some clown on Twitter… it seems crazy he’d write this post without already providing substantial evidence to you guys. Anyway, I understand your position and actually applaud your principles. Hopefully Alex and the victim are able to move quick enough.
English
2
0
2
129
Garry
Garry@elxhick·
@KoaWeb3 bro saved his seed in windows notes 💀💀💀
English
0
0
1
135
Koa.eth
Koa.eth@KoaWeb3·
This crypto millionaire accidentally exposed his wallet seed phrase live on stream. Within seconds, hackers drained over $2.5 million. One mistake... and everything was gone. 🤯
English
16
1
50
4.7K
Garry
Garry@elxhick·
@intangiblecoins @THORChain @Duelcomcasino wrote up more context on how this actually works in the industry x.com/elxhick/status…
Garry@elxhick

This is actually a textbook example of how AML/KYC works at most licensed operators, not the "shady casino" behavior people are reading it as I work in anti-fraud/payments at an online casino myself. A few things worth understanding: Platforms can't freeze funds on a third-party claim alone anyone could accuse anyone of anything and weaponize that to lock random users out of their own money. Requiring a signed message, an affidavit, and a clear evidence trail is exactly the kind of threshold that protects both the platform and legitimate users from that abuse. "We do KYC/AML" doesn't mean every single transaction gets manually reviewed in real time. Most operators run risk-based KYC verification gets triggered by specific flags, not by default on every deposit. On the deposit side specifically, even a $10M deposit might not trigger KYC on its own, because incoming funds are revenue for the platform there's little incentive to slow that down. The real scrutiny almost always shows up on the withdrawal side. What actually matters here isn't whether the bar for freezing exists it's how fast a platform moves once real evidence is in hand. Duel offering an exception without a police report is more than plenty of platforms would do. Fund freezes are the visible part. The part that actually leads somewhere is what happens next pulling KYC documentation and video verification on whoever deposited those funds. That's the step worth watching @Duelcomcasino @intangiblecoins @korraflow

English
0
0
1
772
Garry
Garry@elxhick·
This is actually a textbook example of how AML/KYC works at most licensed operators, not the "shady casino" behavior people are reading it as I work in anti-fraud/payments at an online casino myself. A few things worth understanding: Platforms can't freeze funds on a third-party claim alone anyone could accuse anyone of anything and weaponize that to lock random users out of their own money. Requiring a signed message, an affidavit, and a clear evidence trail is exactly the kind of threshold that protects both the platform and legitimate users from that abuse. "We do KYC/AML" doesn't mean every single transaction gets manually reviewed in real time. Most operators run risk-based KYC verification gets triggered by specific flags, not by default on every deposit. On the deposit side specifically, even a $10M deposit might not trigger KYC on its own, because incoming funds are revenue for the platform there's little incentive to slow that down. The real scrutiny almost always shows up on the withdrawal side. What actually matters here isn't whether the bar for freezing exists it's how fast a platform moves once real evidence is in hand. Duel offering an exception without a police report is more than plenty of platforms would do. Fund freezes are the visible part. The part that actually leads somewhere is what happens next pulling KYC documentation and video verification on whoever deposited those funds. That's the step worth watching @Duelcomcasino @intangiblecoins @korraflow
Korra@korraflow

Hi, Duel team here. We cannot simply freeze a user's funds because a third party claims it is stolen. Anyone can claim anything about someone else's balance. For example, I could swap my BTC for your ETH, claim you robbed me, and get your funds frozen... HOWEVER, I am happy to make a one time exception in this case, because I have sympathy for the Coldcard victims. If the victim is able to sign a message from an address of the "hack," sign an affidavit stating they were hacked, and show the clear trail of evidence leading to Duel, I will temporarily freeze the funds without a police or court order. You have to understand the reason this policy exists, we require SOME sort of official confirmation that an actual theft occured (so confirmation from law enforcement of any kind usually), otherwise anyone can claim stuff about their own balance or a counterparty or a third party they don't even know and get accounts frozen. It would be extremely anti-privacy, anti-crypto, and anti-bitcoin to freeze a balance because someone in support chat asked us to. I am hoping the crypto crowd of all people will understand why we try to preserve sanctity of on-site balances. But as noted, just this once, an exception is open. The alleged victim can send me the above details in DM and I'll get it done. Terrible situation and I have huge sympathy for scam victims but again we have to protect our users and abide by the law, balances on Duel are extremely sacred and it takes a fairly high threshold for us to seize them (essentially we have to be legally obliged to).

English
0
0
1
1.2K
Garry
Garry@elxhick·
@korraflow work in iGaming anti-fraud myself, so I get exactly where you're coming from freeze conditions are reasonable, standard bar most operators set. and credit where due, offering an exception here is the right call hoping your risk team pulls full KYC docs/video verification on whoever deposited those funds, not just a freeze maybe that's the part that actually leads somewhere
English
0
0
6
2.2K
Garry
Garry@elxhick·
@CTI__Updates Seen similar mail:pass-to-wallet pipelines feed into casino/exchange onboarding fraud too stolen creds validated, then used to pass KYC or fund accounts. Same infra, different endpoint
English
0
0
1
69
Garry
Garry@elxhick·
@cloudz haha yeah, good to see you around glad you’re doing good broski 🙏
English
0
0
0
24
cloudz
cloudz@cloudz·
crazy I started in crypto 4 years ago as a Discord moderator now I get to do this full time, working with some of the best projects in the space came a long way grinding through every market condition Solana truly changed my life
English
19
1
85
3.8K
Garry
Garry@elxhick·
@zeke0_19d668 @itscoachgoodman the whole point of ColdCard is that it generates entropy securely for u, this wasn’t “trusting a third party” it was a firmware bug in the device made specifically for this
English
1
0
0
73
ZeKe0
ZeKe0@zeke0_19d668·
@elxhick @itscoachgoodman no he didn’t follow every best practice, why are people saying this. This was common knowledge 13 years ago, don’t trust someone to generate your keys for you
English
1
0
0
163
Jonathan Goodman 🇨🇦
Jonathan Goodman 🇨🇦@itscoachgoodman·
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack. My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet. This part's nerdy, but here's what happened: Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases. This allowed them to use AI to brute force guessing seed phrases. I was at our cottage and heard about the hack today. "No way this affects me." I thought. I logged into Wasabi––software that lets me view my bitcoin wallets online. Right away I saw lines of red transaction–withdrawals–and I knew. From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied. 18.25245043 btc gone. That's just over $1.6 million dollars CAD. Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability. I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything. A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen. I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.
Jonathan Goodman 🇨🇦 tweet media
English
3.9K
2.7K
33.5K
6.2M
Garry
Garry@elxhick·
@glxyresearch @intangiblecoins the behavior doesn’t really fit a typical state-actor playbook (usually compromised signers, social eng) pure entropy exploit feels more like a solo technical actor tbh
English
3
0
5
2.6K
Galaxy Research
Galaxy Research@glxyresearch·
🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained. Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses. More updates in the thread below 👇
Galaxy Research tweet media
Galaxy Research@glxyresearch

We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below. We are now tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across 7 attacker addresses. Updates to our analysis from yesterday 👇

English
85
228
958
670K
Garry
Garry@elxhick·
@Cointelegraph now guess it’s gate’s turn to announce they’re “shutting down the platform” too😭
English
0
0
6
1.9K
Cointelegraph
Cointelegraph@Cointelegraph·
🚨 BIG: Gate saw $547M inflows in the past 24 hours. That's $471M more than the next highest net inflows.
Cointelegraph tweet media
English
101
72
769
128K
Garry
Garry@elxhick·
@XMRVoid fr, this week kinda proves the point tbh 💀
English
0
0
1
1.7K
Mav
Mav@XMRVoid·
Hot wallets on IPhones are okay If you’re worried, use a second phone to store your crypto Hardware wallets are a psyop
English
60
24
431
61.4K
Garry
Garry@elxhick·
@intangiblecoins @glxyresearch curious if you're seeing any early signals on the 7 new addresses from the second wave, or still too early to tell
English
0
0
0
26
Galaxy Research
Galaxy Research@glxyresearch·
We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below. We are now tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across 7 attacker addresses. Updates to our analysis from yesterday 👇
Galaxy Research tweet media
Galaxy Research@glxyresearch

We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett 1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks 960,183-960,191. That preceded the hardware-wallet vendor's public advisory by ~30 hours. Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output. That looks like an automated tool spending keys it already held, not owners moving funds. Victims: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44 — consistent with multi-path key scanning. Proceeds consolidated within minutes and have NOT moved since: - bc1qq85v2c9...cu9r — 562.02 BTC - bc1qx76cae2...fhe3 — 398.48 BTC - bc1q8jy96fe...tp3q — 89.62 BTC - bc1qnk4zh9q...fecp0 — 32.45 BTC (unmoved)

English
25
63
298
189.1K
-null-
-null-@Null_S0L·
This Nigeria trader thought he was selling a coin but he was spam clicking BUY mistakenly Instead of selling before the rug he was aping his life savings mid rug $50,000 down the drain😭😭😭😭
English
35
3
176
63.4K
Tony Meatballs
Tony Meatballs@simmering_chef·
@elxhick @mechanakamoto NVK is a plant brought in to destroy self custody. Built trust for 10 years then dropped a bomb before government regulation voting
English
1
0
1
45
Mecha Nakamoto
Mecha Nakamoto@mechanakamoto·
Bitcoiners What U think about the ColdCard thing? Be real
English
171
1
58
14K
Cyber Scrilla
Cyber Scrilla@CyberScrilla·
I use a mix of cold wallets. @tangem @trezor and @Ledger being my go to I also enjoy @OneKeyHQ I’ve never been a fan of bitcoin only wallets Mainly because it’s just marketing for Bitcoin maxis which I am not Plenty more user friendly and secure options that’s not coldcard
Cyber Scrilla tweet media
English
19
2
99
11.5K