I anticipated more responses and questions from fellow community members, so I’ve been waiting for others to weigh in. Meanwhile, to gather further details on this unfortunate situation and help ease any concerns, I’ll pose a few questions myself.
1. What specific types of information might have been stored on the compromised laptop that could pose risks, such as cryptocurrency keys, customer data, intellectual property related to Polymerbit’s physical notes, or access credentials to business accounts? How could these exposures impact users in the broader crypto community?
2. What justifies alerting the community about this incident if it doesn’t directly involve leaks of Polymerbit product details, customer personal information, or sensitive financial data? Could indirect risks, such as potential phishing campaigns or malware propagation through impersonated communications, warrant the warning?
3. Is the compromise limited to Polymerbit’s accounts (e.g., forums like BitcoinTalk, social media, email, or X/Twitter), or does it extend to the laptop’s local files, connected devices, or broader systems? What evidence from the incident description suggests one over the other?
4. What are the potential benefits and drawbacks of publicly alerting the community in this scenario, and under what conditions would such an alert be warranted only if there’s a substantiated reason for concern, rather than precautionary?
This is a precaution. 1. The biggest risk is that telegram, certain passwords and WhatsApp may have been compromised for about 72h. But log data does not show any entry during this period. Others have reported a strike on their accounts in 1-2 weeks. I'm sounding the alarm to be on the safe side. Keys are not stored on the Mac.
2. I broadcasted this warning as a precaution.
Biggest issue could be that my accounts may suddenly ask you to join a zoom call or ask for money. Which I will never do. Physical addresses of clients are only stored with prior agreement (due to GDPR) and are not stored locally on the laptop.
3. The accounts are what is at risk (including bitcointalk, mail, x, banking). No connected devices affected, because they weren't connected during or after this SDK attack.
Keep an eye out for suspicions requests. 4. The main drawback is causing panic, but the pros far outweigh the cons.
It's my responsibility to always consider the worst case scenario.