News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highBitcoin / CEXphishing

Reported ~$750k CEX drain: Google account + Authenticator cloud (not Coldcard RNG)

15 Aug 2026: A close friend of the victim reported that a Coldcard Mk4 holder moved an entire ~$750k Bitcoin stack onto a well-known Australian exchange and that it was withdrawn in under 12 hours. Bitcoin News amplified the same thread: attackers had the Google account for about three months, including cloud-backed Google Authenticator, waited for the deposit, and the venue treated the withdrawal as the real owner; the victim reportedly saw an approval ping around 3 a.m. Verify: Unverified — friend-of-victim plus pickup, no named exchange, no explorer tx, no AU regulator or venue statement. The Authenticator class is independently real: 2023 cloud sync is not end-to-end encrypted, and as of March 2026 Google still had no E2EE update (Wirecutter). This is a CEX login / 2FA-cloud story, not the Coldcard seed-entropy sweep on the board.

369 take: A hardware wallet does not protect coins once they sit on an exchange whose login and 2FA live in the same Google account. Cloud-backed Authenticator is a spare set of codes for whoever holds that account — keep it offline if you use it, prefer a physical security key (two keys), and do not dump a cold stack onto a CEX because of a hardware scare. Pulse lesson: if your second factor syncs to the same cloud as your email, it is not a second factor.