Live data from Hacker News

Vitalik Buterin reveals X account hack was caused by SIM-swap attack

cointelegraph.com

11–20 of 187 posts

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#11
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

They were probably time limited. No long games. Smash and grab.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#14
post #5

When I read that once they got into the account all the attacker did was post a link to a crypto giveaway scam, I briefly wondered why someone who managed to get into an account like this wouldn’t try to pivot it into something more sophisticated. Then in the next sentence we learn they made $700k off of the scam! I’ve seen these giveaway scams on hacked popular Twitter accounts for years, I’m surprised they’re still…

Using the account of probably one of the few trustworthy people in crypto probably helps.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#16

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

Just having a phone number added to Twitter means your account is at risk of being taken over with a sim-swap. This was not 2FA related AFAICT. Twitter also requires you to add a phone number, even on old accounts you can get locked out unless you add one.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#18
post #4
post #3

Doesn't Xitter require you to have a paid account to use SMS authentication? So one way to secure your account is to refuse to pay for Blue.

"A phone number is sufficient to password reset a Twitter account even if not used as 2FA " This sucks because Twitter will sometimes force you to link a phone number to the account if it doesn't like your VPN or whatever

> "A phone number is sufficient to password reset a Twitter account even if not used as 2FA"

In other words, they don't have a 2FA system. They have a 1FA system, and the only factor is your phone number.

This is a weird choice, since people are much more likely to know your phone number than they are to know your password.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#19

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

It is good to know that hardware wallets such as Trezor and Ledger supports 2FA protocols so if you have one there is no need to use another device.

Re: Vitalik Buterin reveals X account hack was caused by SIM-swap attack

#20

Twitter has had support for proper TOTP based 2FA ever since Jack Dorsey got SIM Swapped in 2019[1]. This was also the time when they added support for hardware tokens like Yubikeys. Of course, one needs to enable it. [1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...

I'm a bit paranoid about 2FA ever since my charging port got damaged and I literally couldn't charge my phone to get to authentication.

Scary stuff, had to give sooo much personal information over the course of months to recover a single account.

Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?

Post reply on HN