2020 Twitter bitcoin scam
This article documents a current event. Information may change rapidly as the event progresses, and initial news reports may be unreliable. The latest updates to this article may not reflect the most current information. (July 2020) (Learn how and when to remove this template message)
A representative scam tweet, from Apple's account. The bitcoin address has been obscured.
|Date||July 15, 2020, 20:00-22:00 UTC|
|Target||Verified Twitter accounts|
|Outcome||Scammers received at least US$110,000 worth of bitcoins|
On July 15, 2020, between 20:00 and 22:00 UTC, a number of high-profile Twitter accounts, each with millions of followers, were compromised in a cyberattack to promote a bitcoin scam. The scam asked individuals to send bitcoin currency to a specific cryptocurrency wallet, with the promise that money sent would be doubled and returned. Based on sources speaking to Vice and TechCrunch, the perpetrators had gained access to Twitter's administrative tools so that they could alter the accounts themselves and post the tweets directly, with the access gained either possibly through paying off Twitter employees to use the tool, or from a compromised employee's account to access the tool directly.
As of July 16, 2020[update], more than 12 bitcoins (BTC or ₿) had been sent to one of the addresses involved, the equivalent of more than US$110,000. Minutes after the tweets were posted, more than 320 transactions had already taken place on one of the wallet addresses.
Dmitri Alperovitch, the co-founder of cybersecurity company CrowdStrike, described the incident as "the worst hack of a major social media platform yet." Security researchers expressed concerns that social engineering that may have been used to execute the hack can affect the use of social media in important online discussions, including the lead-up into the 2020 United States presidential election.
Incident[edit source | edit]
Forensic analysis of the scam showed that the initial scam messages were first posted by accounts with short, one- or two-character distinctive names, such as "@6". This was followed by cryptocurrency Twitter accounts at around 20:00 UTC on July 15, 2020, including those of Coinbase, CoinDesk and Binance. The scam then moved to more high-profile accounts with the first such tweet sent from Elon Musk's Twitter account at 20:17 UTC. Other apparently compromised accounts included those of individuals such as Barack Obama, Joe Biden, Bill Gates, Jeff Bezos, MrBeast, Michael Bloomberg, Warren Buffett, Floyd Mayweather, Kim Kardashian, and Kanye West, and companies such as Apple, Uber, and Cash App. Twitter believed 130 accounts were affected; most of the accounts that were accessed in the scam had at least a million followers.
The tweets involved in the scam hack claimed that the sender, in charity, would repay any user double the value of any bitcoin they sent to given wallets, often as part of a COVID-19 relief effort. The tweets followed the sharing of malicious links by a number of cryptocurrency companies; the website hosting the links was taken down shortly after the tweets were posted. While such "double your bitcoin" scams have been common on Twitter before, this is the first major instance of them being used with high-profile accounts. Security experts believe that the perpetrators ran the scam as a "smash and grab" operation: knowing that the intrusion into the accounts would be closed quickly, the perpetrators likely planned that only a small fraction of the millions that follow these accounts needed to fall for the scam in that short time to make quick money from it. Multiple bitcoin wallets had been listed at these websites; the first one observed had received more than US$118,000 in bitcoin and had about US$61,000 removed from it, while a second had amounts in only the thousands of dollars as Twitter took steps to halt the postings. It is unclear if these had been funds added by those led on by the scam, as bitcoin scammers are known to add funds to wallets prior to starting schemes to make the scam seem legitimate. Of the funds added, most had originated from wallets with Chinese ownerships, but about 25% came from United States wallets. After it was added, the cryptocurrency was then subsequently transferred through multiple accounts as a means to obscure their identity.
Some of the compromised accounts posted scam messages repeatedly, even after having some of the messages deleted. The tweets were labelled as having been sent using the Twitter web app. One of the phrases involved in the scam was tweeted more than 3,000 times in the space of four hours, with tweets being sent from IP addresses linked to many different countries. The reused phrasing allowed Twitter to remove the offending tweets easily as they took steps to stop the scam.
By 21:45 UTC, Twitter released a statement saying they were "aware of a security incident impacting accounts on Twitter", and that they were "taking steps to fix it". Shortly afterwards, it disabled the ability for some accounts to tweet, or to reset their password; Twitter has not confirmed which accounts were restricted, but many users with accounts Twitter had marked as "verified" confirmed that they were unable to tweet. Approximately three hours after the first scam tweets, Twitter reported they believed they had resolved all of the affected accounts to restore credentials to their rightful owners. Later that night, Twitter CEO Jack Dorsey said it was a "tough day for us at Twitter. We all feel terrible this happened. We're diagnosing and will share everything we can when we have a more complete understanding of exactly what happened".
Method of attack[edit source | edit]
As Twitter was working to resolve the situation on July 15, Vice was contacted by at least four individuals claiming to be part of the scam and presented the website with screenshots showing that they had been able to gain access to a Twitter administrative tool that allowed them to change various account-level settings of some of the compromised accounts, including confirmation emails for the account. This allowed them to set email addresses which any other user with access to that email account could initiate a password reset and post the tweets. These hackers told Vice that they had paid insiders at Twitter to get access to the administrative tool to be able to pull this off.
TechCrunch reported similarly, based on a source that stated some of the messages were from a member of a hacking forum called "OGUsers", who had claimed to have made over US$100,000 from it. According to TechCrunch's source, this member "Kirk" had reportedly gained access to the Twitter administrative tool likely through a compromised employee account, after initially offering to take over any account on request, switch strategies to target cryptocurrency accounts starting with Binance and then high-profile ones. The source did not believe Kirk had paid a Twitter employee for access.
The "@6" Twitter had belonged to Adrian Lamo, and the user maintaining the account on behalf of Lamo's family reported that the agency that performed the action were able to bypass numerous security factors they had set up on the account, including two-factor authentication, further indicating that the admistrative tools had been used to bypass the account security. Spokespersons for the White House stated that President Donald Trump's account, which may have been a target, had extra security measures implemented at Twitter after an incident in 2017, and thus was not affected by the scam.
Vice's and TechCrunch's sources were corroborated from other security researchers who had been given similar screens, and tweets of these screens had been made, but Twitter removed these since they revealed personal details of the compromised accounts. Twitter subsequently confirmed that "We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools." In addition to taking further steps to lock down the verified accounts affected, Twitter said they have also begun an internal investigation and have limited employee access to their system administrative tools as they evaluate the situation, as well as if any additional data was compromised by the malicious users.
Perpetrators[edit source | edit]
Security researcher Brian Krebs corroborated with TechCrunch's source and with information obtained by Reuters that the scam appeared to have originated in the "OGUsers" group. The OGUsers forum ("OG" standing for "Original Gangster") was established to legitimately trade social media accounts with short names, and according to its owner, speaking to Reuters, the practice of trafficking in hacked credentials was prohibited. Screenshots from the forum show various users on the forum offering to hack into Twitter accounts at US$2,000-3,000 each. Krebs stated one of the members may have been tied to the August 2019 takeover of Dorsey's Twitter account. The OGUsers owner told Reuters that the accounts shown in the screenshots were since banned.
The Federal Bureau of Investigation (FBI) announced the following day it was launching an investigation into the scam, as it was used to "perpetuate cryptocurrency fraud", a criminal offense. The Senate Select Committee on Intelligence also planned to ask Twitter for additional information on the hack, as the committee's vice-chair Mark Warner stated "The ability of bad actors to take over prominent accounts, even fleetingly, signals a worrisome vulnerability in this media environment, exploitable not just for scams but for more impactful efforts to cause confusion, havoc and political mischief". The UK's National Cyber Security Centre said its officers had reached out to Twitter regarding the incident.
Reaction[edit source | edit]
Affected users retained the ability to retweet content, leading NBC News to set up a temporary non-verified account so that they could continue to tweet, retweeting "significant updates" on their main account. Joe Biden's campaign stated to CNN that they were "in touch with Twitter on the matter", and that his account had been "locked down".
Security experts expressed concern that while the scam may have been relatively small in terms of financial impact, the ability for social media to be taken over through social engineering involving employees of these companies poses a major threat in the use of social media particularly in the leadup to the 2020 United States Presidential election, and could potentially cause an international incident. Alex Stamos of Stanford University's Center for International Security and Cooperation said "Twitter has become the most important platform when it comes to discussion among political elites, and it has real vulnerabilities."
BitTorrent CEO Justin Sun announced a US$1 million bounty against the hackers. The announcement was made on BitTorrent's Twitter account, and added that "He will personally pay those who successfully track down, and provide evidence for bringing to justice, the hackers/people behind this hack affecting our community."
References[edit source | edit]
- Iyengar, Rishi (July 15, 2020). "Twitter accounts of Joe Biden, Barack Obama, Elon Musk, Bill Gates, and others apparently hacked". CNN Business. Retrieved July 15, 2020.
- "Musk and Gates 'hacked' in apparent Bitcoin scam". BBC News. July 15, 2020. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- Sheth, Sonam (July 15, 2020). "Former President Barack Obama's Twitter account appears to have been hacked as part of a cryptocurrency scam". Business Insider. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Cox, Joseph (July 15, 2020). "Hackers Convinced Twitter Employee to Help Them Hijack Accounts". Vice. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- Whittaker, Zack (July 15, 2020). "A hacker used Twitter's own 'admin' tool to spread cryptocurrency scam". TechCrunch. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Leswing, Kif (July 15, 2020). "Hackers appear to target Twitter accounts of Elon Musk, Bill Gates, others in digital currency scam". CNBC. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- "Twitter accounts of Elon Musk, Barack Obama, Bill Gates and more hacked in bitcoin scam". SBS News. July 15, 2020. Archived from the original on July 16, 2020. Retrieved July 16, 2020.
- Guynn, Jessica (July 16, 2020). "'Tweet-tastrophe'? It could have been. Twitter hack reveals national security threat ahead of election". USA Today. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Frenkel, Sheera; Popper, Nathaniel; Conger, Kate; Sanger, David E. (July 15, 2020). "A Brazen Online Attack Targets V.I.P. Twitter Users in a Bitcoin Scam". The New York Times. Archived from the original on July 16, 2020. Retrieved July 16, 2020.
- Isaac, Mike; Frenkel, Sheera; Conger, Kate (July 16, 2020). "Twitter Struggles to Unpack a Hack Within Its Walls". The New York Times. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Whittaker, Zack. "High-profile Twitter accounts simultaneously hacked to spread crypto scam". TechCrunch. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- Statt, Nick (July 15, 2020). "Barack Obama, Joe Biden, Elon Musk, Apple, and others hacked in unprecedented Twitter attack". The Verge. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Holmes, Aaron; Leskin, Paige (July 15, 2020). "Hackers took over dozens of high-profile Twitter accounts including those of Barack Obama, Joe Biden, Elon Musk, Kim Kardashian, and Apple and used them to post bitcoin scam links". Business Insider. Retrieved July 15, 2020.
- Woodward, Alex (July 15, 2020). "Elon Musk, Apple, Bill Gates, Kanye West and more hacked by cryptocurrency scam". The Independent. Retrieved July 15, 2020.
- Ingram, David; Collier, Kevin. "Biden, Gates, Musk: Bitcoin scam breaches some of world's most prominent Twitter accounts". NBC News. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- Lawler, Richard (July 16, 2020). "Twitter says attackers targeted 130 accounts in Wednesday's breach". Engadget. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Mac, Ryan; Lytvynenko, Jane (July 15, 2020). "Joe Biden, Elon Musk, And Barack Obama's Twitter Accounts Were Hacked In A Bitcoin Scam". Buzzfeed News. Archived from the original on July 15, 2020. Retrieved July 15, 2020.
- Price, Rob (July 15, 2020). "Some of the world's biggest Twitter accounts are hacked. Here's what we do and don't know about what's going on right now". Business Insider. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Frier, Sarah; Tong, Sebastian (July 15, 2020). "Twitter Hack Snags Obama, Biden, Gates Accounts in Bitcoin Scam". Bloomberg. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- "Twitter accounts of Biden, Obama and other prominent figures hacked". The Irish Times. July 15, 2020. Retrieved July 15, 2020.
- Twitter Support [@TwitterSupport] (July 15, 2020). "We are aware of a security incident impacting accounts on Twitter. We are investigating and taking steps to fix it. We will update everyone shortly" (Tweet) – via Twitter.
- Gartenberg, Chaim (July 15, 2020). "Twitter has shut off the ability for some people to tweet after massive hack". The Verge. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Couts, Andrew (July 15, 2020). "Twitter Finally Blocks the Worst of Us from Tweeting". Gizmodo. Archived from the original on July 16, 2020. Retrieved July 15, 2020.; Sanders, Chris; Driver, Anna (July 15, 2020). "Twitter silences some verified accounts after wave of hacks". Yahoo News. Reuters. Retrieved July 15, 2020.; Gartenberg, Chaim (July 15, 2020). "Twitter has shut off the ability for some people to tweet after massive hack". The Verge. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- Iyengar, Rishi (July 15, 2020). "Twitter blames 'coordinated' attack on its systems for hack of Joe Biden, Barack Obama, Bill Gates and others". CNN. Retrieved July 16, 2020.
- Lucky225 (July 16, 2020). "The Twitter Hack — What exactly happened?". Medium. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- @TwitterSupport (July 15, 2020). "Coordinated Social Engineering Attack" (Tweet). Retrieved July 15, 2020 – via Twitter.
- @TwitterSupport (July 15, 2020). "Internal Tool Lockdown" (Tweet). Retrieved July 15, 2020 – via Twitter.
- Bell, Karissa (July 16, 2020). "Twitter hack reportedly originated with posts on a gray market forum". Engadget. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Krebs, Brian (July 16, 2020). "Who's Behind Wednesday's Epic Twitter Hack?". Krebs on Security. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Setter, Raphael; Menn, Joseph (July 16, 2020). "Before hack tore through Twitter, online forum offered accounts for sale". Reuters. Retrieved July 16, 2020. CS1 maint: discouraged parameter (link)
- Menn, Joseph; Hosinball, Mark (July 16, 2020). "Exclusive: U.S. FBI is leading an inquiry into the Twitter hack, sources say". Reuters. Archived from the original on July 16, 2020. Retrieved July 16, 2020.
- "Major US Twitter accounts hacked in Bitcoin scam". BBC News. July 16, 2020. Archived from the original on July 16, 2020. Retrieved July 16, 2020.
- Lee, Nicole (July 15, 2020). "Twitter has apparently disabled tweets from verified accounts". Engadget. Retrieved July 15, 2020.
- Matney, Lucas (July 15, 2020). "Twitter stock slides after-hours amid scramble to contain high-profile account hacks". TechCrunch. Archived from the original on July 16, 2020. Retrieved July 15, 2020.
- World, Republic. "BitTorrent CEO Justin Sun announces $1 million bounty on Bitcoin scammers, decries hacking". Republic World. Retrieved July 16, 2020.; "BitTorrent Inc. Bounty Tweet". Twitter. Archived from the original on July 16, 2020. Retrieved July 16, 2020.
TRON Founder & CEO of @BitTorrent, Justin Sun is putting out a Bounty for the hackers in the amount of $1 million.CS1 maint: discouraged parameter (link)
[edit source | edit]
Visibility[edit source | edit]
This page has been added to search engine indexes. learn more