Prediction: the most prominent ColdCard retirement attack thief sells substantial portions of the stolen funds directly to the miner fee using onchain transactions with no outputs or very small outputs (huge miner fee) shortly after the BIP-110 mandatory signalling height.
If there is a chainsplit, they may or may not mix the stolen coins they control with a coin derived from the coinbase on one or the other branch of the split so to commit that transaction ONLY to that side, whether keeping the coin for himself or giving it up to the miner fee, or (less likely except in case of collusion) sending to another entity. This will allow the attacker to pick which chain to support or dump on, via miner subsidy (short term burst in mining profitability) or via dumping if colluding with a large liquidity custodial entity like an exchange or treasury company to make the coins effectively saleable (could be coordinated by unaccountable state agents infiltrating/working with major Bitcoin companies).
Login to reply