Maybe. Someone moved the HEX and ETH out 10 h ago. Did he gave the seed phrase to a scammer?
Does the account it got sent to look shady? He’s never given out his seed
Then he probably had his keys in a hot wallet on a Windows machine or some other no-no thing.
Doesn't look like a typical thief's address.
Why would they send ETH to my mates account first before cleaning it out?
Because otherwise they wouldn't be able to clean it up. This is not typical thief behavior. It may have been someone that had access to his paper wallet or his computer.
Oh they sent ETH to use as gas fee to empty out his wallet? That’s fucked
A random thief would unlikely do that as there's a lot of thieves that specialize on stealing from wannabe thieves using the honeypot scam. That's why it possible that the thief knows him and possibly found his paper wallet or got access to the computer with the hot wallet. Also because professional thieves would immediately swap to ETH or stablecoins.
He’s currently travelling round Australia. He uses his mobile. But it be if he connected to a dodgy wifi anywhere?
Huh, a hot wallet on a mobile? Well, I guess for small amounts.
Is his mobile number registered in a country where a SIM swap is possible? eg USA?
Is sim swap a thing in Australia? That’s where we are
Обсуждают сегодня