Hackers still actively tweeting out from everyone's accounts https://twitter.com/search?q=All%20Bitcoin%20sent%20to%20the...
is it just me or are they now mass altering users' names? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
Hackers take over prominent Twitter accounts in simultaneous attack
721–730 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#722Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#723Earlier quoted context omitted.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
Someone got mugged with their phone unlocked and the mugger had a friend who was into bitcoin.
"...from the accounts of Gemini, Binance, KuCoin, Coinbase, Litecoin's Charlie Lee, Tron's Justin Sun, Bitcoin, Bitfinex, Ripple, Cash App, Elon Musk, Uber, Apple, Kanye West, Jeff Bezos, Michael Bloomberg, Warren Buffett, Barack Obama and CoinDesk."
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#724The scammer's address: https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n...
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#725My bet is on one of those social media managers like Hootsuite/Social Blade/Buffer getting hacked.
Looks like Hootsuite Twitter integration has been having issues for 50 mins now https://status.hootsuite.com/post/623750375373160449/twitter... .
Or maybe it was a multipronged attack that included social media management software and OAuth
but the hilarious most visible solution is that Twitter now disabled all verified accounts
and they should keep it that way
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#726Watch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.
Given the Twitter web interface is just an client of the Twitter semi-public API, I highly doubt this is it.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#727Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#728Re: Hackers take over prominent Twitter accounts in simultaneous attack
#729Earlier quoted context omitted.
If they had full access to Twitter’s backend, they probably would be tweeting from accounts like @POTUS or @jack. But this seems like they have access to limited accounts. Most likely gained access to a third party service that allows you to manage your tweets? Edit: they tweeted from the twitter support account. Just wow. They might have actually gotten into Twitter’s systems. Edit 2: To expand on my edit above, I s…
You say they'd target POTUS but of the very high profile accounts it's so far billionaires, corporations and democrat politicians. Does make you wonder.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#730Hopefully, an eventual post-mortem is gonna be juicy and then we can critique all we want.