> After investigation I discovered that 20 different accounts had sent a transaction to the attacker’s address, but only 9 were accounts which previously reused a nonce. What about the other 11? How did the attacker get their money? I’m not sure.
Perhaps a transaction reusing a nonce made it to the mempool, but the attacker, watching the mempool, immediately submitted (or even cooperated with a mining pool to) a transaction emptying the sending account, using a much larger fee to push out the other transaction. That would leave no trace of the nonce reuse on chain.