0x60dc5bb0…e470sent to0xee009faf…c8c5·#16,989,417·view on Etherscan
If I had known it would turn out like this, I wouldn't have gotten involved in helping these guys. It turns out they weren't true to their word and the promised reward was just a honeypot to gather as much information as possible. The exploiter had bad opsec and didn't even keep the 10% from the original deal. I'm not sure who I contacted before; it could have been two people. The exploiter is most likely a young solidity developer.
Another possibility is that this could have been a publicity stunt as an insider didn't want the recovery to be done. In the end, there are two possibilities: either the attacker had bad opsec and their behavior was analyzed and used against them, possibly through threats in emails or other means, or this was a publicity stunt to increase credibility and trust.