The Chinese printer malware targets only legacy addresses, because they've been lurking and stealing since before segwit?

The Chinese printer malware targets only legacy addresses, because they've been lurking and stealing since before segwit?

r/computerviruses reported the malware stealing bitcoin.

Its code was targeting only legacy addresses on Base58:
([13][a-km-zA-HJ-NP-Z1-9]{25,34})

But it's very easy to include Bech32 as well. For example:
(bc1[a-z0-9]{25,87}|[13][a-km-zA-HJ-NP-Z1-9]{25,34})

According to a professional analyst, only the code of the first image was sent: https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads

I wonder why they did only legacy addresses.

My guess is that they had been hiding and stealing for over eight years, before Segwit, and only discovered it this year. The second image shows 2017 tx.

But could there be other reasons?

submitted by /u/_tea_two to r/Bitcoin
[link] [comments]
Quelle: bitcoin-en