Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

591–600 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#591

Earlier quoted context omitted.

Nope. They're actually getting away with quite a big loot! The number of unconfirmed transactions has catapulted from ~9k to about ~50k right now, which means there's large amount of activity. It will take a while for the dust to settle. You can watch them here https://www.blockchain.com/btc/unconfirmed-transactions chart https://www.blockchain.com/charts/mempool-count A better graph of the current transactions sitti…

So we're likely talking some 50-100 million of dollars being stolen? Insane.

It's only at 12 bitcoin ($120k) right now. (serious question) why do you think it could be as high as $50 to $100 mm? Is there a way to see the total including unconfirmed transactions?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#592

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Inkl bite: lets say I hack capable of doing this. How do I sell my hack?

Walk into the [country] embassy, probably (or twitter these days...)

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#593
post #452

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Maybe the dude shorted the Twitter stock?

Bad idea for the hacker. Stock ownership is public information.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#594

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

100k USD? Twitter's payouts aren't that impressive, https://hackerone.com/twitter

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#595

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

What was done was a guaranteed method of getting the method/exploit fixed in record time. If the perpetrator wanted to demonstrate, they would have targeted someone inconsequential that would not have put the problem on twitters radar. They blew their whole wad, likely on purpose, and there is nothing else planned.

Yeah, the idea that this is an initial step in something bigger doesn't make sense.

If they wanted to exfiltrate data, they already did that previously.

They very loudly burned their access, this seems a lot more like someone trying to monetize their access quickly before their access token expires - squeezing out the last few drops before they can no longer get into the system.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#596

Earlier quoted context omitted.

113k is a little reward?

Twitter would have probably paid out about $100k for this to be reported via a bug bounty program. $100k is nothing for the risk taken, they could have made a lot more.

Twitter should have paid millions for a bug like this.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#597
post #215
post #94

Earlier quoted context omitted.

They haven't yet gone after the most prominent Twitter user.

One wonders if that specific account has some unique exemption in the Twitter code to specifically deal with it.

I'd assume that, too. Given the sheer impact a tweet from him might have, there are probably (hopefully!) two extra layers.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#598

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

Pros: no taxes

Cons: trying to deal with 103k in bitcoin

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#599

Twitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.

Many powerful actors, including state actors, would love to see Twitter, as a political instrument, go away. It could even be our own, or a dissident group within our own, IC. If someone can get a presidential candidate and an ex-president's twitter account to say what they want, then that is pretty much the end of Twitter as a political tool.

Didn't one such person and a prominent user just publicly say a lot against Twitter?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#600
post #541

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

I’m guessing DMs were the real loot. The public display with the BTC diversion validates any DMs that were stolen. Otherwise blackmail targets could deny them.

Interesting theory, but this widespread hack pretty much gives most people plausible deniability in my opinion.
Post reply on HN