More

    X Password-Recovery Attack Targeted Hundreds of Thousands of Users


    • DOJ and X are jointly investigating a large-scale password recovery attack.
    • Hundreds of thousands of X accounts were targeted, none reportedly compromised.
    • Hijacked crypto-related accounts are often used to spread fake airdrop scams.

    Hundreds of thousands of X users were targeted in an attempted password-recovery attack this week, according to U.S. Attorney General Todd Blanche.

    X disrupted the attack before the accounts could be compromised, and the Justice Department is now working with the company to identify those responsible.

    Sponsored

    Crypto Prediction Markets

    18+ · Gambling involves risk. Play responsibly.

    The incident is particularly relevant to crypto users, whose X accounts can serve as direct channels for promoting fake token giveaways, airdrops and malicious links.

    How the Attack Targeted X Users

    Blanche described those behind the campaign as “sophisticated cybercriminals” but did not disclose how the attack was carried out or identify any suspected individuals or groups.

    A password-recovery attack exploits the “forgot password” or account-recovery process rather than trying to crack users’ existing passwords, allowing attackers to attempt account takeovers at scale. 

    These attacks often exploit the SMS or email verification step in account recovery and use automated attempts to target large numbers of accounts at once.

    Blanche also confirmed that X successfully blocked the attempt before any accounts were compromised. 

    The full scope of the campaign remains unclear. Neither the DOJ nor X has publicly disclosed the specific technique used, the exact number of accounts targeted or whether particular groups of users were singled out.

    Why Crypto Users Should Pay Attention

    X is a major communication channel for crypto projects, exchanges and industry figures. An account takeover can therefore become more than a social-media security problem: attackers can use a trusted account to impersonate a project or executive and direct followers toward a fake airdrop, fraudulent investment opportunity or malicious website.

    The risk has precedent. In 2024, attackers gained control of the U.S. Securities and Exchange Commission’s X account in a SIM-swap incident and used it to publish a false announcement about the approval of spot Bitcoin ETFs.

    How to Protect Your X Account From Passwor-Recovery Attacks

    Do not use links in unsolicited X password-reset emails. Access X directly and enable Password Reset Protect under Settings > Security and account access > Security.

    Enable 2FA with an authenticator app or hardware security key rather than SMS. This adds protection if attackers attempt to exploit the account-recovery process.

    Why This Matters

    The massive password-recovery attack was stopped before X accounts were compromised, but the campaign shows why account-recovery systems can be attractive targets at scale. For crypto users, protecting an X account is also about protecting a channel that can be used to influence followers and move money.

    Discover DailyCoin’s popular crypto news today:
    Japan’s 10Y Bond Yield Hits 3%. Why Bitcoin Should Pay Attention
    XRP Edges Bitcoin Across Korea’s Top Platforms

    DailyCoin’s Vibe Check: Which way are you leaning towards after reading this article?





    Source link

    Latest stories

    You might also like...