Why the missing post-mortem matters
Most records in this tracker end with a technical account of what failed. This one does not, and that absence is the finding.
When a custodial exchange is breached, the company can make customers whole; the root cause matters for prevention but not for recovery. When a non-custodial wallet is compromised, the keys were on the user’s device. Without a published root cause, a user cannot answer the only question that matters to them: is my remaining key material still safe, and was the exposure in the application, the build pipeline, the random number generation, or somewhere else entirely?
What Conisec will not do
Several plausible mechanisms were proposed publicly at the time. We are not going to repeat them as findings. A guessed root cause on a security publication becomes a citation somewhere else, and users make key-rotation decisions on it. We record what was established and mark the rest Disputed.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- Users report drained balances; Atomic Wallet acknowledges the reports and begins investigating. Atomic Wallet
What to check
Atomic Wallet's own statements are the record. Conisec does not restate a root cause that has not been authoritatively established.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Atomic Wallet, Official statements (3 Jun 2023)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.