Twitter Hack
What happened
On July 15, 2020, attackers took over 130 Twitter accounts, including those of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple, Binance and Coinbase, and used 45 of them to tweet a "double your bitcoin" scam. The New York Department of Financial Services (NYDFS) put the take at over $118,000 in bitcoin; the U.S. Justice Department counted 415 transfers worth more than $117,000. Merkle Science traced 12.86 BTC from 323 transactions into the main scam address alone.
No malware or software exploit was involved. The attackers phoned Twitter employees posing as the IT help desk, collected their VPN credentials and MFA approvals through a look-alike phishing site, and reached internal support tools that could change any account's email address and security settings.
Cryptocurrency companies limited the damage. Coinbase, Gemini and Square blocked the scam addresses within 40 minutes of their own accounts being hijacked, and Coinbase alone stopped about 5,670 transfers worth roughly $1.29M. Graham Ivan Clark (17, Florida) was charged as the mastermind, with Mason Sheppard (19, UK) and Nima Fazeli (Florida) charged federally.
Main scam address: bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh
How it happened
- On July 14, 2020, the attackers called Twitter employees claiming to be from the IT help desk and responding to a VPN problem.
- They sent employees to a phishing site that mimicked Twitter's VPN login, replayed the entered credentials on the real site in real time, and got some employees to approve the resulting MFA prompt.
- The first compromised employee lacked account-management access, so the attackers used it to read intranet pages and learn which staff could reach the internal tools, then targeted those employees on July 15.
- With tool access, they hijacked and sold short "OG" usernames, then took over crypto-industry accounts from about 3:18 p.m. and celebrity and corporate accounts from about 4:17 p.m. to 6:05 p.m., tweeting bitcoin addresses that promised to double any payment.
- They also accessed DM inboxes of up to 36 accounts and downloaded "Your Twitter Data" archives for 7 accounts.
- Twitter restricted verified accounts from tweeting and cut back employee access to internal tools to stop the attack; accounts could mostly tweet again by 8:41 p.m.
Protocol details
Evidence
- report Report coindesk.com
- report @lawmaster incident report twitter.com
- report @cameron incident report twitter.com
- report Report theverge.com
- report Twitter Investigation Report (NYDFS, October 2020) dfs.ny.gov
- address www.blockchain.com address bc1qxy…0wlh blockchain.com
- analysis Accused Twitter hacker arrested in Florida; two others charged (CyberScoop) cyberscoop.com
- analysis UPDATED: Hack Track: #Twitterhack bitcoin scam (Merkle Science) merklescience.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.