Earlier quoted context omitted.
Nope. They're actually getting away with quite a big loot! The number of unconfirmed transactions has catapulted from ~9k to about ~50k right now, which means there's large amount of activity. It will take a while for the dust to settle. You can watch them here https://www.blockchain.com/btc/unconfirmed-transactions chart https://www.blockchain.com/charts/mempool-count A better graph of the current transactions sitti…
So we're likely talking some 50-100 million of dollars being stolen? Insane.
Hackers take over prominent Twitter accounts in simultaneous attack
581–590 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#582Earlier quoted context omitted.
Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?
This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#583Notable that Trump is not impacted. If you had backdoor access to any Twitter account, why on earth wouldn't you tweet as Trump?
Another possibility is that they are indeed just after the money and compromising Trump's account would prompt a faster response from Twitter (possibly taking down the entire account or platform) and reduce the effectiveness of the scam.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#584Earlier quoted context omitted.
Maybe a front end/OAuth issue - those are not uncommon either. Will be interesting to learn more. Also begs the question, who is liable in such cases....
Liable for the account being compromised? Twitter. Liable for people sending money? People sending money.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#585Earlier quoted context omitted.
Twitter almost certainly self-hosts GitHub, no?
Don't know, but current corporate dogma is to not host anything, including using third party auth provider which is like giving away their customer list.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#586Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#587Earlier quoted context omitted.
I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.
If DMs were the real loot, they wouldn’t have exposed the hack by tweeting on the account.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#588Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#589Earlier quoted context omitted.
I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.
If DMs were the real loot, they wouldn’t have exposed the hack by tweeting on the account.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#590Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
mafia boy 2.0
I literally just signed up to reply to this.