Each step of that runs on the attacker’s machine. The sufferer’s system is just not concerned at any level and could possibly be powered off in a secure on one other continent.
Galaxy’s breakdown reveals the method working. Of the drained wallets, 1,183 used the trendy native segwit handle format, seven used an older customary and 6 an older one nonetheless. No one targets a selected sufferer throughout three handle codecs without delay.
That’s systematic enumeration, checking every candidate seed towards each path it may need produced. The operator can widen the search, refine it and return each time they select.
Galaxy warned additional waves are possible if house owners don’t transfer their funds.

Nor can an proprietor decide whether or not they’re uncovered. There isn’t any check to run towards your individual pockets that reveals whether or not your seed sits contained in the reproducible vary.
Assault won’t be totally completed
Coinkite, Coldcard’s maker, has warned Mk3 house owners and says its newer gadgets are unaffected, whereas Block’s report locations the Mk2, Mk4, Q and Mk5 in scope as properly. Till that’s resolved, anybody who generated a seed on the affected firmware has to imagine the worst slightly than confirm it.
The attacker did make one mistake, nevertheless.
Block’s Clay Garrett mentioned on X that the operator used a paid account at a “well-known blockchain information supplier” to question the supply addresses in the course of the sweeps, and that the supplier’s inside logs matched the suspected workflow with what he referred to as extraordinary specificity, all the way down to the quantity, timing and sequence of requests.
