A Bitcoin holder lost about $750,000 in BTC less than 12 hours after depositing the coins at a centralized exchange, with GoPlus linking the theft to a compromised Google account and Google Authenticator cloud sync that let attackers access the exchange account and empty it. The funds had just been moved from a Coldcard MK4 hardware wallet, shifting the point of failure from offline custody to online account security. Earlier reporting from Bitcoin News, citing a friend of the holder, said attackers had controlled the Google account for about three months and described the venue as a major Australian exchange, while GoPlus said the compromise unfolded within 12 hours of the transfer. GoPlus said attacks of this kind usually rely on phishing, stolen browser cookies or passwords, credential stuffing against reused weak passwords, or takeovers of recovery email addresses and phone numbers rather than brute-force methods.