I noticed something when I tried asking questions: whether calling this an “anomalous activity” right at the start of an alert is shaping how people feel about the severity before they even have the chance to know any details.
“Anomalous activity” is a fairly neutral phrase—broadly applicable to anything from a minor technical glitch to a large-scale exploitation. Meanwhile, an independent tracker uses “unauthorized actor draining”—wording that is more vivid and far more suggestive of active, serious wrongdoing, even though it describes the same sequence of events. The choice of wording in the opening sentence often carries more weight than the sentences that follow.
This is a form of linguistic anchoring—it's not necessarily false, but it picks the lowest level of severity within the range of labels that could be used. Both ways of phrasing can be correct about the event, but they anchor the reader’s emotions to two very different points on the severity scale.
@Dusk is not an isolated case when it comes to selecting softened language—this is almost a general standard when organizations draft incident statements with legal implications. But the gap between the two ways of naming it is large enough to create two very different narratives in the reader’s mind, depending on which source they come across first.
Self-refutation: this is an observation about general language choices, not proof that $DUSK intentionally picks words to mislead—“anomalous activity” could simply be the consistent internal terminology used for every incident.
I’m waiting to see whether any truly neutral third party summarizes the chain of events in a more objective language, so it can be compared with both of the current versions rather than being read through only one side’s lens.
#dusk $BTC $ETH