TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hackers take over prominent Twitter accounts in simultaneous attack

2595 pointsby megadethalmost 5 years ago

218 comments

dangalmost 5 years ago
All: don&#x27;t miss that there are multiple pages of comments. The top few subthreads have become so large that they fill out the first page entirely. You have to click &#x27;More&#x27; at the bottom to see the rest, including a lot of the newest posts. Or use these links:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=2" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=2</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=3" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=3</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=4" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851275&amp;p=4</a><p>Edit: also, there&#x27;s a related thread tracking the BTC transactions here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851542" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23851542</a>.<p>In general, look for More links at the bottom of big threads. This is a performance workaround that we&#x27;re hoping to drop before long, but in the meantime there&#x27;s a limit of 250 or so comments per page.
BiteCode_devalmost 5 years ago
Given how huge this hack is, and how little the BTC reward is going to be, I&#x27;m tempting to think this is either:<p>- a test of a new hacking system<p>- a demonstration to a big client<p>- a first shot to threat some entity<p>- a diversion while they get the real loot<p>And that the BTC messages are just a way to justify it so it looks like a simple scam.<p>Such a hack is worth way, WAY more than the few BTC it could bring.
评论 #23852535 未加载
评论 #23853146 未加载
评论 #23853108 未加载
评论 #23853117 未加载
评论 #23855092 未加载
评论 #23852533 未加载
评论 #23855609 未加载
评论 #23852864 未加载
评论 #23852429 未加载
评论 #23856489 未加载
评论 #23852814 未加载
评论 #23858219 未加载
评论 #23852789 未加载
评论 #23856578 未加载
评论 #23852479 未加载
评论 #23852518 未加载
评论 #23855162 未加载
评论 #23853526 未加载
评论 #23853107 未加载
评论 #23853428 未加载
评论 #23852608 未加载
评论 #23852859 未加载
评论 #23855561 未加载
评论 #23856758 未加载
评论 #23856660 未加载
评论 #23854480 未加载
评论 #23852912 未加载
评论 #23853090 未加载
评论 #23855813 未加载
评论 #23852503 未加载
评论 #23853609 未加载
评论 #23852710 未加载
评论 #23855619 未加载
评论 #23855584 未加载
评论 #23856673 未加载
评论 #23859142 未加载
评论 #23857356 未加载
评论 #23852965 未加载
评论 #23852614 未加载
评论 #23852517 未加载
评论 #23856824 未加载
评论 #23855804 未加载
评论 #23856520 未加载
评论 #23852989 未加载
评论 #23853951 未加载
评论 #23852653 未加载
评论 #23852491 未加载
评论 #23853241 未加载
评论 #23852620 未加载
评论 #23855495 未加载
评论 #23853155 未加载
评论 #23854619 未加载
评论 #23853660 未加载
评论 #23852885 未加载
neurostimulantalmost 5 years ago
With so many accounts compromised, the hackers might actually have full access to Twitter&#x27;s backend. The postmortem would be very interesting. I&#x27;ll be looking forward to it.<p>Imagine if the hackers timed the intrusion during github outage, and twitter&#x27;s employees can&#x27;t deploy a fix for the exploit fast enough because github was down!
评论 #23852853 未加载
评论 #23852976 未加载
评论 #23852403 未加载
评论 #23852471 未加载
评论 #23852044 未加载
评论 #23852335 未加载
评论 #23852285 未加载
评论 #23855213 未加载
评论 #23852041 未加载
评论 #23853782 未加载
评论 #23852922 未加载
评论 #23852219 未加载
评论 #23852656 未加载
评论 #23852256 未加载
评论 #23857748 未加载
评论 #23856788 未加载
评论 #23853733 未加载
评论 #23852446 未加载
评论 #23857974 未加载
评论 #23852174 未加载
评论 #23852327 未加载
blisseyGoalmost 5 years ago
Tweet from TwitterDev team yesterday:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283068902331817990" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283068902331817990</a><p>&gt; 2 days to go… #TwitterAPI<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283433096780677122" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283433096780677122</a><p>&gt; Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Early Access is coming tomorrow!<p>Were they supposed to launch some new API tomorrow which got hacked?
评论 #23854571 未加载
评论 #23853669 未加载
评论 #23853624 未加载
评论 #23854489 未加载
评论 #23853662 未加载
评论 #23853989 未加载
评论 #23854913 未加载
iambenalmost 5 years ago
Elon Musk as well. Tweets still up, saying &quot;Feeling greatful, doubling all payments sent to my BTC address!<p>You send $1,000, I send back $2,000! Only doing this for the next 30 minutes.&quot;<p>As of now, 121 people have sent cash totally more than 2.5BTC.<p>Edit: Just seen @BillGates compromised as well, same bitcoin account.<p>Edit 2: Elon&#x27;s tweet seems to be getting removed, and then reposted again shortly after. About $40k sent so far.<p>Edit 3: Interesting to watch - on both accounts, tweets seem to be deleted and then reappear as pinned a few mins later.
评论 #23851723 未加载
评论 #23851704 未加载
评论 #23851604 未加载
评论 #23851460 未加载
评论 #23851833 未加载
评论 #23852148 未加载
评论 #23852182 未加载
评论 #23851584 未加载
评论 #23852206 未加载
评论 #23852546 未加载
评论 #23852326 未加载
评论 #23851383 未加载
评论 #23852160 未加载
评论 #23851832 未加载
jsnellalmost 5 years ago
Just what kind of an operation is Twitter running here? It seems crazy that they don&#x27;t have any kind of anti-abuse system in place that could just block tweets with this specific Bitcoin address or possibly tweets matching the regexp of any Bitcoin address. I.e. limit the damage and buy a couple of hours while they try to find the root cause.<p>(Yes, yes, staged rollouts. But anti-abuse systems don&#x27;t work by those rules, at least in emergencies.)
评论 #23852555 未加载
评论 #23858327 未加载
评论 #23854753 未加载
评论 #23852029 未加载
评论 #23852147 未加载
评论 #23852268 未加载
评论 #23852869 未加载
评论 #23852232 未加载
DevX101almost 5 years ago
Twitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.
评论 #23852609 未加载
评论 #23852983 未加载
评论 #23852795 未加载
评论 #23853008 未加载
评论 #23853059 未加载
评论 #23852812 未加载
withinrafaelalmost 5 years ago
Verified Twitter user here: Locks [1] are in place, attempting to tweet throws an error: Something went wrong, but don&#x27;t fret -- let&#x27;s give it another shot.<p>At the bottom of the page, a notification appears: This request looks like it might be automated. To protect our users from spam and other malicious activity, we can&#x27;t complete this action right now. Please try again later.<p>[1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;1283526400146837511" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;128352640014683751...</a><p>Direct Messaging is still functional as of 523PM PDT.
评论 #23854647 未加载
评论 #23859161 未加载
throw_m239339almost 5 years ago
Your site is getting hacked, you don&#x27;t know how the hackers are doing it, what do you do ops wise? Take the whole site down for a few hours? Because the entire platform is compromised, how do you handle that?
评论 #23853226 未加载
评论 #23852355 未加载
评论 #23852598 未加载
评论 #23855581 未加载
评论 #23854582 未加载
评论 #23853048 未加载
Reason077almost 5 years ago
So many accounts are affected, this seems to be a system-level hack rather than a compromise of individual accounts.<p>Someone has found a way to post a tweet from any account they like?
评论 #23851737 未加载
评论 #23851660 未加载
评论 #23851557 未加载
评论 #23851588 未加载
评论 #23851576 未加载
评论 #23851544 未加载
评论 #23851556 未加载
davidlee1435almost 5 years ago
Kudos to Coinbase- I tried sending a small amount to the account after seeing Elon Musk&#x27;s tweet, and Coinbase prevented the transaction from occurring.
评论 #23853777 未加载
评论 #23852350 未加载
评论 #23854801 未加载
评论 #23852191 未加载
评论 #23852475 未加载
rvzalmost 5 years ago
Uber has been hacked as well. At this point, they can get any high profile Twitter user.<p>EDIT: You know this is a coordinated Twitter hack when they have Apple&#x27;s account hacked [0]. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;Apple&#x2F;status&#x2F;1283506278707408900" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Apple&#x2F;status&#x2F;1283506278707408900</a>
评论 #23851867 未加载
评论 #23851775 未加载
评论 #23851769 未加载
评论 #23852095 未加载
VikingCoderalmost 5 years ago
Watch this turns out to be a JS dependency tree problem from some library that was compromised months ago in some NPM module, used in the twitter web interface.
评论 #23852627 未加载
评论 #23852409 未加载
评论 #23854597 未加载
shiadoalmost 5 years ago
Place your bets, phishing or bug exploit. Some of these targets are too high profile to all fall for it and probably have teams that manage these accounts securely. Edit: 2fa was bypassed, interesting. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;tylerwinklevoss&#x2F;status&#x2F;1283492017889259523" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;tylerwinklevoss&#x2F;status&#x2F;12834920178892595...</a>
评论 #23851566 未加载
评论 #23852489 未加载
评论 #23851585 未加载
评论 #23853050 未加载
评论 #23851567 未加载
评论 #23851605 未加载
评论 #23854911 未加载
Nextgridalmost 5 years ago
Initial postmortem: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;1283591844962750464" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;128359184496275046...</a><p>Seems to be a social-engineering attack on Twitter staff.
评论 #23855826 未加载
评论 #23855977 未加载
jaxxstormalmost 5 years ago
I&#x27;m flabbergasted they haven&#x27;t just hit the panic button and shut everything down.<p>Unless, perhaps, they can&#x27;t.
评论 #23852945 未加载
评论 #23854049 未加载
评论 #23852363 未加载
评论 #23852742 未加载
评论 #23855175 未加载
评论 #23852404 未加载
评论 #23852523 未加载
lesderidalmost 5 years ago
<a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283068902331817990" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterDev&#x2F;status&#x2F;1283068902331817990</a><p>Hmm.
评论 #23853309 未加载
评论 #23853095 未加载
评论 #23853812 未加载
dvtalmost 5 years ago
What blows my mind is how does Twitter not have a &quot;maintenance&quot; mode -- where <i>no new tweets</i> can be posted and the site is essentially read-only?
评论 #23852463 未加载
评论 #23852534 未加载
评论 #23852477 未加载
评论 #23853172 未加载
评论 #23853696 未加载
e79almost 5 years ago
A lot of people are asking “why a bitcoin scam?”<p>From what we know right now, targeted accounts had their emails and 2FA reset via an admin tool. These attacks were noisy, so the window of opportunity for the attacker was small. The attack was launched after hours, likely to limit the chance that the compromised Twitter employee would be around. So market manipulation wasn’t really a great option.<p>This was basically a “smash and grab” style attack, which makes sense given the noisy nature of the access. I wouldn’t be surprised if Twitter’s admin tool purposely doesn’t allow employees to silently access accounts.
评论 #23858992 未加载
trolliedalmost 5 years ago
Loads of accounts still tweeting it in realtime. Follow it live: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&amp;src=typed_query&amp;f=live" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...</a>
评论 #23852053 未加载
评论 #23853228 未加载
评论 #23852476 未加载
rifficalmost 5 years ago
This is what happens when you put all of your communication eggs into a single basket.<p>Twitter needed to be taken down a couple of pegs. I think accounts of a high enough profile may want to closely examine the ActivityPub ecosystem.
评论 #23854084 未加载
评论 #23852770 未加载
评论 #23852779 未加载
tassalmost 5 years ago
Bezos now, too!<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;JeffBezos&#x2F;status&#x2F;1283508547897171969" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;JeffBezos&#x2F;status&#x2F;1283508547897171969</a>
评论 #23852557 未加载
评论 #23851904 未加载
评论 #23852084 未加载
mekkkkkkalmost 5 years ago
Is it just me, or does this seem suspiciously poorly thought out? Perhaps there is a second stage involving stock plays. The BTC thing might be a diversion.<p>Or we are incredibly lucky and the exploit was found by people with really bad foresight and imagination.
评论 #23852626 未加载
评论 #23852711 未加载
etaioinshrdlualmost 5 years ago
Partial list of hacked accounts here, <a href="https:&#x2F;&#x2F;twitter.com&#x2F;Justin12393LEE&#x2F;status&#x2F;1283498445886586883" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Justin12393LEE&#x2F;status&#x2F;128349844588658688...</a><p>Mentions: - Bitcoin - Coinbase - BINANCE - CZ_Binance - Gemini - Kucoin - Gate .io - Coindesk - Tron - Justin Sun - Charlee Lee
评论 #23851459 未加载
评论 #23851495 未加载
deftalmost 5 years ago
The attack is ongoing. Why haven&#x27;t they<p>1) shut down api endpoints 2) locked down all verified accounts 3) blocked any tweets with the btc address in them 4) make a statement if they really can&#x27;t stop it?
dvaunalmost 5 years ago
There&#x27;s a Web Archive link[0] for anyone curious.<p>It looks like this was pretty successful for the hacker. At the time of writing they received ~3.1 BTC, or ~$29k in USD[1].<p>Edit: Replaced [1] with a site that appeared to have less trackers according to Privacy Badger.<p>[0]: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200715202030&#x2F;https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk&#x2F;status&#x2F;1283495825998520320" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200715202030&#x2F;https:&#x2F;&#x2F;twitter.c...</a><p>[1]: <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
clarkmoodyalmost 5 years ago
There is definitely a big red button at Twitter that somebody should have pressed an hour ago.
评论 #23853075 未加载
PatrolXalmost 5 years ago
Twitter is seriously out of control.<p>They should have pulled the plug an hour ago, and that plug pulling should have been automated.<p>If this were something even more sinister a whole country could have plummeted into chaos, death, destruction.
评论 #23853531 未加载
评论 #23852514 未加载
评论 #23852622 未加载
dansoalmost 5 years ago
This is the earliest non-deleted tweet I&#x27;ve found referencing the bitcoin address (or rather, noticing that an account got hacked). It was sent at 12:23PM Pacific time (more than 1.5 hours ago): <a href="https:&#x2F;&#x2F;twitter.com&#x2F;lawmaster&#x2F;status&#x2F;1283481418518208513" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;lawmaster&#x2F;status&#x2F;1283481418518208513</a>
评论 #23852201 未加载
jacquesmalmost 5 years ago
Still going on. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;BillGates&#x2F;status&#x2F;1283503731682811907" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;BillGates&#x2F;status&#x2F;1283503731682811907</a> What a disaster this stuff. Wonder how it was done.
评论 #23851682 未加载
评论 #23851654 未加载
评论 #23851641 未加载
lostmsualmost 5 years ago
This is going to be a hilarious postmortem. If we ever see it.
zetazzedalmost 5 years ago
My wild, unfounded conjecture: the attacker discovered this recently and had only a short, fixed time window in which to run a scam. Maybe the time before some maintenance update? So none of the more sophisticated approaches (like selling to the highest bidder or manipulating some stocks) were practical before the vulnerability would be repaired. If you imagine short notice and a couple-hour window when US markets were closed, are alternative hacks really that much more lucrative?
gfrangakisalmost 5 years ago
Everyone say a prayer for Twitter engineers trying to fix this tonight
rsanheimalmost 5 years ago
WTF. I&#x27;m baffled. How have they not either<p>* thrown the site in read only mode OR<p>* taken the entire site down<p>Until they can fix the security vulnerabilities. That would be better than what is happening now.
abvdaskeralmost 5 years ago
Okay here is my mostly baseless conspiracy theory:<p>As many others have noted, access to the compromised accounts is worth several orders of magnitude more money than the hackers were able to extract using this naive bitcoin scam. Whether it&#x27;s used to manipulate markets or just resold, the hack is probably worth millions or tens of millions. Is it plausible that hackers who could coordinate and execute this kind of a breach would not know how to maximize the value of the hack and would instead opt for a really naive and not especially lucrative BTC scam?<p>It is also pretty common knowledge that the activist investor hedge fund Elliott Management has wanted Jack Dorsey removed as Twitter&#x27;s CEO for quite some time. What if the BTC scam is a cover for corporate espionage? What if the purpose of the hack was actually to make Dorsey look incompetent in the most public way possible, and possibly turn many influential public figures against Twitter? Elliott Management has the resources to finance a breach like this as well as the motive.<p>An alternate theory would be that this actually <i>was</i> a form of market manipulation -- manipulation of Twitter&#x27;s share price.
评论 #23855805 未加载
dluanalmost 5 years ago
for 15 minutes society was perfect, i felt invigorated and had the ability to dream new dreams, and we were all loving friends. and then the blue checks came back.
评论 #23858058 未加载
aeyesalmost 5 years ago
Is the attack now changing usernames to the BTC address or are these people just trolling?<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&amp;src=typed_query&amp;f=live" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...</a>
评论 #23854122 未加载
评论 #23853646 未加载
caiobegottialmost 5 years ago
I&#x27;m honestly surprised that Twitter doesn&#x27;t have some sort of circuit breaking for such gigantic attack towards major accounts. It&#x27;s a PR nightmare that a circuit breaker would help a bit with, no?
评论 #23852153 未加载
rsa25519almost 5 years ago
Obama <a href="https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139</a><p>Also: - Musk - Bill Gates - Apple - Uber - Jeff Bezos - Joe Biden - MrBeast
评论 #23855049 未加载
techaddict009almost 5 years ago
Seems like the hacker has got 100% access to Twitter&#x27;s backend and is just not able to decide whom to attack next!<p>One after another big handles getting hacked!<p>Collection till now has crossed 12 BTC (<a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>)
Me1000almost 5 years ago
It would be incredibly irresponsible if there isn&#x27;t a team at Twitter right now working to bring the whole site down.<p>It&#x27;s one thing going after a couple celebrities and CEOs, but they&#x27;ve now hit a former US President and a current Presidential candidate.
PatrolXalmost 5 years ago
I posted this here and it got flagged.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;asculthorpe&#x2F;status&#x2F;1283501026281127937" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;asculthorpe&#x2F;status&#x2F;1283501026281127937</a><p>Try to warn people and you get slammed for it.<p>Ugh.
blisseyGoalmost 5 years ago
Could this be related to the Executive Order POTUS signed yesterday on Hong Kong Normalization?<p><a href="https:&#x2F;&#x2F;www.whitehouse.gov&#x2F;presidential-actions&#x2F;presidents-executive-order-hong-kong-normalization&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.whitehouse.gov&#x2F;presidential-actions&#x2F;presidents-e...</a>
caiobegottialmost 5 years ago
That&#x27;s really light in details, TC has more juice about the situation IMHO: <a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2020&#x2F;07&#x2F;15&#x2F;twitter-accounts-hacked-crypto-scam&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2020&#x2F;07&#x2F;15&#x2F;twitter-accounts-hacked-cr...</a>
ydnaclementinealmost 5 years ago
The wallet that the hacker who got Elon posted has been given 5.7 BTC and counting: <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
评论 #23852026 未加载
评论 #23851853 未加载
monokhalmost 5 years ago
This must be a twitter exploit. Just too many high profile accounts have been pushing out scams at the same time.
评论 #23852282 未加载
IMAYousafalmost 5 years ago
I have a question to ask you all. If I wanted to study things to get to the point where internally&#x2F;externally I could coordinate a hack of this magnitude, what things do I need to study? What are the technical things needed to pull something like this off? What are the social corporate things I needed to know to pull this off? I know that we don&#x27;t have specifics, but I&#x27;m asking as a pure academic exercise how much I&#x27;d need to know to pull this off, and how to get away with it too.
评论 #23855937 未加载
评论 #23855803 未加载
bayesianbotalmost 5 years ago
Lots and lots of crypto accounts hacked. Either Twitter is hacked or some automated tweeting system has a 0day.
评论 #23851376 未加载
codesternewsalmost 5 years ago
This raises so much questions about Tech giants security. If they could do this manipulating elections or so much power with one system.<p>&quot;Security is Myth.&quot;
Keverwalmost 5 years ago
Wonder if this could have been done by a rogue employee at Twitter? Since they are working from home during COVID, wonder what internal controls they have? I know some wondered if they used serveral high profile accounts, why not the presidents then? Well Twitter put extra protections on his account after an employee on their last day decided to suspend his account for 11 minutes. So if this isn&#x27;t an hack and done internally that might be a clue.<p>I was surprised Apple especially got their account hacked, since they are big on security as a company. I know with Facebook a page can have multiple person accounts managing it, but I don&#x27;t believe Twitter ever had such a thing unless more recently... So if you want multiple people to manage an account you&#x27;d use a special tool or just share the login info between your social media team.<p>I kinda feel like if you have to commute to an office, maybe more accountability as I&#x27;d feel someone might be looking more over your shoulder but I&#x27;d depend if someone gets private offices or a more open office design.
WarOnPrivacyalmost 5 years ago
Posts stopped for the other btc address (bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh)<p>Here&#x27;s a tweet from KimKardashian, for a different BTC address (bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l) <a href="https:&#x2F;&#x2F;twitter.com&#x2F;KimKardashian&#x2F;status&#x2F;1283523054874877953" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;KimKardashian&#x2F;status&#x2F;1283523054874877953</a>
评论 #23853074 未加载
a-wualmost 5 years ago
With the way that Elon tweets normally, someone could have done a lot of damage before anyone realized. Luckily markets have closed already.
评论 #23852143 未加载
nonbirithmalmost 5 years ago
It&#x27;s amusing that this is so successful only because of all the people posting their triumphant screenshots of success in losing all their money.<p>All it takes is 100 gullible people to net $100k, and there&#x27;s a lot more than 100 gullible people on Twitter.<p>And it all happened in the span of 20 minutes. Can we expect any better response in the hopes of preventing this next time assuming all the accounts are hacked already? Or does the nature of realtime media and hundreds of bored eyes sitting on wads of cryptocurrency getting to it first mean it&#x27;s just game over?<p>I remember the golden days of messing up people&#x27;s lives over digital terminals, where the most they&#x27;d do was wipe your harddisk or warn the user of something vaguely ominous on the third Tuesday of April like &quot;the Reaper&#x27;s gonna get you&quot; or play an 80&#x27;s Top Ten number rendered through the PC speaker all of the sudden scaring you to death.<p>From here on out it&#x27;s always going to be about money, and to me that&#x27;s just boring and sad.
评论 #23852221 未加载
throw_m239339almost 5 years ago
Should Twitter start supporting cryptographically signed messages? In any case, I wonder about the legal ramifications of this kind of event, for Twitter and for the individuals that have been hacked.
评论 #23852141 未加载
alvisalmost 5 years ago
It&#x27;s a very very loud attack, no doubt. But how sophisticated it&#x27;s? Probably not as much as many think. As early reports suggest the attack was done via a stolen employee&#x27;s token, it suggests the attacker has access to the employee&#x27;s web browser. Potentially some malware extension that silently sniffs traffic to twitter?
techaddict009almost 5 years ago
Has Twitter&#x27;s forever WFH policy resulted in this Zero Day Vector or Whatever it is! Which has resulted in Hacking of So many big Accounts and Bitcoin Scam?
PatrolXalmost 5 years ago
So far people have sent:<p>Transactions 253<p>Total Received $101,539.14<p>Link to address:<p><a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
评论 #23851968 未加载
vsaretoalmost 5 years ago
All of Apple&#x27;s tweets are gone<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;Apple" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Apple</a>
评论 #23851837 未加载
评论 #23851890 未加载
评论 #23851739 未加载
blablablubalmost 5 years ago
So Twitter&#x27;s killswitch is that verified accounts cant tweet any more...<p>Vive la plebs!
benlumenalmost 5 years ago
<a href="https:&#x2F;&#x2F;twitter.com&#x2F;brandontwall&#x2F;status&#x2F;1283525485440503811" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;brandontwall&#x2F;status&#x2F;1283525485440503811</a><p>Hours in, seems the vulnerability was not yet patched but simply blue-checks had posting rights pulled. Only non-verified accounts have been posting the wallet key for a while now (search new to find them).<p>I know it&#x27;s easy to judge from afar but I can&#x27;t believe they&#x27;re leaving the site up during this.
WarOnPrivacyalmost 5 years ago
The domain associated with first round of tweets wasn&#x27;t anonymized.<p>Could be a setup <a href="https:&#x2F;&#x2F;twitter.com&#x2F;jfbsbnix&#x2F;status&#x2F;1283487977591767041" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;jfbsbnix&#x2F;status&#x2F;1283487977591767041</a><p>Or maybe a dodge <a href="https:&#x2F;&#x2F;twitter.com&#x2F;verretor&#x2F;status&#x2F;1283506654521094146" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;verretor&#x2F;status&#x2F;1283506654521094146</a>
评论 #23852722 未加载
ve55almost 5 years ago
This is looking really bad, I wonder what they used to get access to all these high-profile accounts?<p>It&#x27;s worth noting these types of blackhat crypto scammers make millions a year from this already, but this is definitely making it a lot worse.<p>EDIT: Still going on after 30+ minutes, seeing people like Bill Gates tweet crypto scams still. Amazed they got all the crypto exchange too.<p>And it&#x27;s not just Bitcoin, they got RIpple too and posted XRP addresses.
break_the_bankalmost 5 years ago
Why is twitter optimizing uptime instead of trust?<p>Trying to figure out why would they let such a massive hack play out for over an hour instead of pulling the kill switch.
Laforetalmost 5 years ago
I have a couple of services that run on twitter API and they have all been suspended in the last half hour. They are definitely in damage control mode.
porjoalmost 5 years ago
Recent update: &quot;We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;1283591846464233474" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;128359184646423347...</a>
sch00lb0yalmost 5 years ago
Shameless plug: All the companies(Google, Microsoft...) are telling trust us. But, I believe that we should trust us instead of relying on third parties. They always change when businesses interest changes. This is where web3 is coming to play. Technologies like IFFS, safe network are coming. Looking at the scale issue, I guess this web3 takes at least 5 more years. But, this kind p2p technology is possible with small-scaled mesh. Mesh networks within our devices or families. From the beginning, I hate the idea of storing passwords in the third-party password manager. Later, I fell into the same trap because a managing lot of passwords is difficult. So, I building an open-source p2p password manger. Replicates the passwords within your devices, instead of storing everything at the vendor&#x27;s cloud. It&#x27;s half-way for the closed beta release. I would like to hear everyone&#x27;s feedback on this idea.<p>Thanks
评论 #23856912 未加载
byteshockalmost 5 years ago
Seems like they reposted it on the cash app account. This time it’s a different address.<p>New Address: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w9l <a href="https:&#x2F;&#x2F;mobile.twitter.com&#x2F;CashApp&#x2F;status&#x2F;128352200769559757.." rel="nofollow">https:&#x2F;&#x2F;mobile.twitter.com&#x2F;CashApp&#x2F;status&#x2F;128352200769559757...</a>.
amaialmost 5 years ago
Isn&#x27;t it obvious? All the hacked accounts were fake accounts from the start managed by twitter employees who fill them with content every day to simulate an active social network. The hack just revealed that Twitter in fact rules the world and all these other companies, billionaires and celebrities simply don&#x27;t exist.
shaabanbanalmost 5 years ago
Imagine for a moment that this ends up being something state-sponsored or that twitters entire DB gets dumped, private accounts and all.<p>This could have a profound impact on governments who want to target dissidents if somebody for example, only felt comfortable criticizing their government from a protected account...
vmceptionalmost 5 years ago
My bet is on one of those social media managers like Hootsuite&#x2F;Social Blade&#x2F;Buffer getting hacked.
评论 #23854060 未加载
评论 #23852267 未加载
tedk-42almost 5 years ago
Btc address in the explorer to see how much was deposited <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
whoisjuanalmost 5 years ago
Whoever hacked Twitter today definitely got major access to their backend: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;whoisjuan&#x2F;status&#x2F;1283502962103455744?s=20" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;whoisjuan&#x2F;status&#x2F;1283502962103455744?s=2...</a>
评论 #23851589 未加载
rudolph9almost 5 years ago
I was thinking the other day about a digital signature for limited character tweets.<p>Provided I’m not a cryptography expert and you should explore my ideas with caution, why not even just sign every tweet with an ed25519 signature? It’s on 64 bytes tacked onto the message and easy to verify...
评论 #23855484 未加载
评论 #23854406 未加载
评论 #23853945 未加载
aqme28almost 5 years ago
About $110k in the address. Honestly not that impressive for a hack of this scale. I wonder what they could have gotten if they reported this for a bug bounty instead.<p>Or as Matt Levine said, &quot;if I got Elon Musk&#x27;s twitter password I&#x27;d wait until market hours to use it.&quot;
评论 #23852507 未加载
hosainnetalmost 5 years ago
This reminds me of Colin.<p>Back in 2013 when I was working at Sky News, the person responsible for the social media accounts (with millions of followers in total) stormed into a meeting: &quot;Our Twitter account has been hacked&quot;.<p>This was at a time when many high-profile news Twitter accounts were hacked by so-called &quot;electronic armies&quot; who published damaging tweets. However in our case it was a single obscure &quot;Colin was here&quot; tweet.<p>We had recently built an internal endpoint in one of the backend apps that takes a string and publishes it straight to the main breaking news Twitter account. This was integrated with a custom UI tool that the news desk people used to quickly break a story across TV, Twitter, the website etc with one click.<p>I had a suspicion that this endpoint was how that tweet was published, but could not prove it. Many thoughts were going through my head.. “is this an internal job, or did someone hack our backend system and somehow figured this out etc.. “<p>We quickly returned to our desks, and straight away I greped our logs for &quot;tweeting&quot; as I developed that feature and was sure we logged that when the endpoint is called, but in the heat of the moment forgot that to “-i” as it the log message actually contained &quot;Tweeting&quot; (which cost us a few minutes). In the meantime there was panic around the business, people were putting out PR statements just in case it was a real hack, the tweet was deleted etc.<p>Finally, with help from colleagues, we tracked down a &quot;Tweeting&quot; log message around the same time the tweet was published along with the HTTP request source IP, and traced it (just like in movies) to our secondary news studio in Central London. This is when one of the managers shouted &quot;I know a Colin who works there, he&#x27;s a testing team manager!&quot;.<p>We gave Colin a ring to understand what was going on, he had no idea about any of this but said he was doing some DR testing earlier of all tools that editors use, and wasn’t really aware this would go out. As you can imagine, it could have been much worse.<p>The entertaining bit was the 30 minutes of fame this mysterious Colin enjoyed on the internet, where many people were worried about the welfare of &quot;Colin&quot;, and it was picked up by various [1] news [2] websites.<p>[1] <a href="https:&#x2F;&#x2F;www.buzzfeed.com&#x2F;lukelewis&#x2F;an-important-history-of-the-colin-was-here-meme-that-changed" rel="nofollow">https:&#x2F;&#x2F;www.buzzfeed.com&#x2F;lukelewis&#x2F;an-important-history-of-t...</a> [2] <a href="https:&#x2F;&#x2F;www.buzzfeed.com&#x2F;lukelewis&#x2F;an-important-history-of-the-colin-was-here-meme-that-changed" rel="nofollow">https:&#x2F;&#x2F;www.buzzfeed.com&#x2F;lukelewis&#x2F;an-important-history-of-t...</a>
epaalmost 5 years ago
Archive of Elon&#x27;s tweet <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200715203559&#x2F;https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200715203559&#x2F;https:&#x2F;&#x2F;twitter.c...</a>
d--balmost 5 years ago
Why isn&#x27;t twitter taking its infrastructure down?
评论 #23852270 未加载
malikNFalmost 5 years ago
This &quot;send me btc to send you more btc&quot;scam has been happening for the past few months and Charles Hoskinson (<a href="https:&#x2F;&#x2F;twitter.com&#x2F;IOHK_Charles" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;IOHK_Charles</a>), founder of the Cardano blockchain was warning about this issue for a while, he mentioned his team was trying to get in touch with twitter and youtube to stop this and these companies have let this slide for a while.<p>[edit]<p>some are wondering if this is some type of money laundering scheme <a href="https:&#x2F;&#x2F;twitter.com&#x2F;nktpnd&#x2F;status&#x2F;1283521742602940420" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;nktpnd&#x2F;status&#x2F;1283521742602940420</a>
评论 #23854727 未加载
blisseyGoalmost 5 years ago
Strange coincidence tweet by Jack Dorsey from last evening:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;jack&#x2F;status&#x2F;1283169859233214465" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;jack&#x2F;status&#x2F;1283169859233214465</a><p>&gt; #bitcoin @BubbaWallace
retzkekalmost 5 years ago
&gt; “I am giving back to my fans. All Bitcoin sent to my address below will be sent back doubled.”<p>So Twitter is the real-life Jita local chat? Does this also mean BTC is as meaningless as ISK, that people are willing to gamble it on a doubling scam?
blisseyGoalmost 5 years ago
This reminds me of 2013 when The Associated Press was hacked with a tweet of &quot;Breaking: Two Explosions in the White House and Barack Obama is injured&quot; and erased $136 billion in equity market value:<p>Archive: <a href="http:&#x2F;&#x2F;archive.is&#x2F;8lCMV" rel="nofollow">http:&#x2F;&#x2F;archive.is&#x2F;8lCMV</a><p><a href="https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;news&#x2F;worldviews&#x2F;wp&#x2F;2013&#x2F;04&#x2F;23&#x2F;syrian-hackers-claim-ap-hack-that-tipped-stock-market-by-136-billion-is-it-terrorism&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;news&#x2F;worldviews&#x2F;wp&#x2F;2013&#x2F;04&#x2F;23...</a>
chkialmost 5 years ago
Wouldn&#x27;t it be possible to block this attack by flagging all tweets containing the Bitcoin address in question? I would&#x27;ve assumed that Twitter could do something like this, maybe even already set up an automated system.
评论 #23854796 未加载
Inversechialmost 5 years ago
Twitter support thread: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;1283591844962750464" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;128359184496275046...</a>
jacquesmalmost 5 years ago
The title is inaccurate. The Twitter accounts hacked are <i>far</i> more important than just a couple of prominent cryptocurrency accounts.<p>Obama is in there, Jeff Bezos, Bill Gates and many other prominents that have nothing to do with crypto.
elwellalmost 5 years ago
All @apple tweets removed?<p><pre><code> @Apple hasn’t Tweeted When they do, their Tweets will show up here. </code></pre> <a href="https:&#x2F;&#x2F;twitter.com&#x2F;Apple" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Apple</a>
评论 #23852821 未加载
评论 #23852794 未加载
pcbro141almost 5 years ago
Pics of tweets: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TheHackersNews&#x2F;status&#x2F;1283502081265950720" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TheHackersNews&#x2F;status&#x2F;128350208126595072...</a>
评论 #23851510 未加载
techaddict009almost 5 years ago
Finally Twitter wakes up and Twitter support tweets: &quot;You may be unable to Tweet or reset your password while we review and address this incident.&quot;<p>Not clear who is You here, all accounts are just verified or selected accounts.
embitalmost 5 years ago
I am sorry but either from the article or discussion here, I am not exactly clear what has happened. Can someone explain ? Meaning did the user accounts on Twitter got hacked or the actual company websites ? Or both ?
评论 #23853834 未加载
pagadealmost 5 years ago
Elon Musk again - <a href="https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk&#x2F;status&#x2F;1283520825782566912" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk&#x2F;status&#x2F;1283520825782566912</a>
AgentK20almost 5 years ago
Jeff Bezos just got hit as well:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;JeffBezos&#x2F;status&#x2F;1283508547897171969" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;JeffBezos&#x2F;status&#x2F;1283508547897171969</a>
rsecoraalmost 5 years ago
They are posting to almost every other account, high profile or not. Its a massive spam, too much users to be a password steal.<p>About the client, they are post from accounts that have only used &quot;Twitter for Web&quot; or only used &quot;Twitter for Mac&quot; or only used &quot;Twitter for iPhone&quot;... in the past<p>Updated accounts with the spam.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh%20filter%3Averified&amp;src=typed_query&amp;f=live" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...</a>
WarDoresalmost 5 years ago
Multiple folks on Twitter saying all verified accounts have been locked.
abhiminatoralmost 5 years ago
The BTC address used by the malicious actors has received ~13 BTC so far. That&#x27;s around $120k in value at the time of me writing this comment.<p>Not sure if such a massive, simultaneous hacking operation makes sense for ~$120k worth of BTC. As other commenters mentioned, postmortem of this one should be interesting.<p><a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
MattGaiseralmost 5 years ago
Obama too:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139</a>
adjkantalmost 5 years ago
Listing some out that I&#x27;ve seen:<p>@Apple @Uber @elonmusk @kanye @MikeBloomberg @JoeBiden @WarrenBuffet @wizkhalifa @BarackObama @JeffBezos @MrBeastYT @FloydMayweather @LuckyovLegends @xxxtentacion
woliveirajralmost 5 years ago
Worldwide verified accounts are now disable (can favorite and retweet but not post messages), and I imagine that soon we&#x27;ll see unverified accounts also being targeted.
break_the_bankalmost 5 years ago
Obama just tweeted out the same thing. It seems all of twitter has been hacked. The post mortem will sure be interesting. Also interested in how TWTR gets affected.
vs4vijayalmost 5 years ago
If you take a look at some of the transactions, you will see some interesting addresses like:<p>1JustReadALL1111111111111114ptkoK<p>1TransactionoutputsAsTexta13AtQyk<p>1YouTakeRiskWhenUseBitcoin11cGozM<p>1BitcoinisTraceabLe1111111ZvyqNWW<p>1WhyNotMonero777777777777a14A99D8<p>1forYourTwitterGame111111112XNLpa<p>Link: <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;tx&#x2F;67b814526ae6ee78a16059bfcfc06ed7768c92c58f3409367cb180627631ddbe" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;tx&#x2F;67b814526ae6ee78a16059bfcf...</a>
jliptzinalmost 5 years ago
Seems to me twitter should hire some humans to sit there and manually approve every tweet by all VIP accounts before they go live. How hard could that be? If that’s all they do you’re adding maybe a 30 second delay to every VIP tweet and you’re pretty much guaranteeing that this doesn’t happen again. Unless of course the hackers somehow inserted the tweet directly to the database and bypassing any such measures.
评论 #23855110 未加载
ISLalmost 5 years ago
Oh wow, now they&#x27;re doing multiple tweets&#x2F;minute: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&amp;src=typed_query&amp;f=live" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...</a><p>It might make sense for Twitter to redirect all non-retweets of that address to &#x2F;dev&#x2F;null (or a sandbox) for a little while.
评论 #23851943 未加载
_5659almost 5 years ago
I do not think it is hyperbolic at all that I immediately just felt the hand move a full minute towards midnight.<p>This is suspiciously underwhelming use of an exploit.
caretak3ralmost 5 years ago
People who don&#x27;t want scrutiny from their old tweets want an easy way to delete&#x2F;wipe their tweets. There are a load of software out there that claim to do this. They all relatively take over the oAuth chain, and do the needful. But one of them does it as if you were in your browser. As to not give away information about the user&#x27;s phone&#x2F;type&#x2F;version.
评论 #23855084 未加载
caretak3ralmost 5 years ago
It&#x27;s so easy for a Twitter user to use a a later compromised 3rd party app, only having to press a button to authorize the entire oauth chain. Look at hosted packages or artifacts in dockerhub, GitHub, ruby, pypi, etc. Malicious things like this are everywhere, dormant on systems until the right group can leverage against end users. Imagine if tweekdeck was compromised.
s5300almost 5 years ago
Still going on as of this post time. Elon&#x27;s just went off again.<p>Over 30ish minutes now. Holy shit, it&#x27;s going to be fun to see the outcome of this.
korethralmost 5 years ago
So, has twitter deleted all the bogus tweets at this point? I have clicked on multiple links just to see a bunch of context-less replies.
fortran77almost 5 years ago
I can&#x27;t imaging some of those hacked people not having extremely good security habits. 2FA, long unique ramdom-generated passwords not used anywhere else, and secured phones that would be hard to do a SIM swap on.<p>Which leads me to believe someone has really hacked twitter in a bad way or there&#x27;s someone on the inside helping them.
miguelmotaalmost 5 years ago
Hackers still actively tweeting out from everyone&#x27;s accounts<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;search?q=All%20Bitcoin%20sent%20to%20the%20address%20below%20will%20be%20sent%20back%20doubled&amp;src=typed_query&amp;f=live" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;search?q=All%20Bitcoin%20sent%20to%20the...</a>
评论 #23853488 未加载
blauditorealmost 5 years ago
Funnily enough, the Tweet made me immediately think whoever wrote it speaks French natively. In French grammar, there needs to be space before any punctuation with exactly two parts (e.g. &quot;:&quot;, &quot;!&quot;, or &quot;?&quot;), and it&#x27;s a common error for French-natives to do the same in English.
brunoluizalmost 5 years ago
Just imagine if they have to shutdown twitter momentarily —- it has been a long time since the last big fail whale
willfiveashalmost 5 years ago
I&#x27;m guessing use of 2FA internally could have prevented this intrusion but that&#x27;s a hassle so...
caetris1almost 5 years ago
My original comment was deleted, so I&#x27;ll try this again.<p>I&#x27;ve read the comments here and quite surprisingly there are a lot of folks saying that the value of this hack isn&#x27;t worth more than roughly one year&#x27;s salary at Twitter (as an intern). I appreciate the pragmatism, but unlikely.<p>Anyone with this kind of exploit could have sold it, moved to Russia, and received immunity from extradition. Secondly, people should be scrutinizing any moron willing to give away thousands of dollars to billionaires for a promise of a 2x return. Especially in these times.<p>So, reason can only allow us to arrive at a most likely cause. That this was indeed an inside job. It was not about money. It was not a security flaw. But rather, it was simply a group of employees that were unhappy with Twitter allowing the federal government to investigate bad actors on the platform behind closed doors.<p>And here is why: <a href="https:&#x2F;&#x2F;www.scribd.com&#x2F;document&#x2F;467148777&#x2F;DHS-Social-Media-Letter" rel="nofollow">https:&#x2F;&#x2F;www.scribd.com&#x2F;document&#x2F;467148777&#x2F;DHS-Social-Media-L...</a>
评论 #23854971 未加载
DevX101almost 5 years ago
I could imagine a faked tweet attributed to Trump that could immediately begin mobilization in other countries to prepare for war. There are several fake tweets from the Bezon&#x2F;Musk I could imagine that could credibly send the stock price of AMZN down by 10%, TSLA down by 50% in a matter of minutes.<p>Attacker(s) could profit immensely if they had leveraged short positions cleverly placed.<p>Users losing a few hundred thousand is getting off light considering the severity of this attack and how much worse it could have been.
lpellisalmost 5 years ago
Does this mean they can also login to any account connected with OATH. Many sites allow Twitter auth.
knownalmost 5 years ago
According to Blockchain.com, more than $100,000 was received at that address about an hour after the first hack, which appears to have tricked more than 350 users. <a href="https:&#x2F;&#x2F;archive.vn&#x2F;QOp4M" rel="nofollow">https:&#x2F;&#x2F;archive.vn&#x2F;QOp4M</a>
Hongweialmost 5 years ago
This may be the last straw that tips politicians over into considering Twitter &amp; co utilities - stuff that the gov has a say in running because failure is unacceptable to the public.<p>Not that I think the gov could do a better job, but that doesn&#x27;t stop them elsewhere.
Miner49eralmost 5 years ago
The scammer&#x27;s address: <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh?page=1" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
评论 #23854168 未加载
watsonalmost 5 years ago
Here&#x27;s an official update from Twitter: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;1283591844962750464" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TwitterSupport&#x2F;status&#x2F;128359184496275046...</a>
SwiftyBugalmost 5 years ago
The attacker already made over 5 BTC:<p><a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;bc1qxy2kgdygjrsqtzq2n...</a>
评论 #23851716 未加载
评论 #23851648 未加载
评论 #23851665 未加载
satkinalmost 5 years ago
Looks like verified users can tweet again: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TaylorLorenz&#x2F;status&#x2F;1283531947877294082" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TaylorLorenz&#x2F;status&#x2F;1283531947877294082</a>
pwdisswordfish2almost 5 years ago
Poll: Will this affect your trust in Twitter as a source of information? If no, why not?
surroundalmost 5 years ago
Instead of taking a screenshot, archive Tweets with <a href="https:&#x2F;&#x2F;archive.is&#x2F;" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;</a> before they disappear. (The Wayback machine doesn’t work with Twitter due to robots.txt)
dsr12almost 5 years ago
Hackers still posting using Elon&#x27;s account: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk&#x2F;status&#x2F;1283520825782566912" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;elonmusk&#x2F;status&#x2F;1283520825782566912</a>
pcbro141almost 5 years ago
Some pics of the tweets: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TheHackersNews&#x2F;status&#x2F;1283502081265950720" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TheHackersNews&#x2F;status&#x2F;128350208126595072...</a>
arberavdullahualmost 5 years ago
I am wondering if the hackers had access to the private messages of these accounts?
meaydinlialmost 5 years ago
Please be kind to the people that are working on this problem, right now, at Twitter and the countless hours that will need to go into remedying it.<p>Hopefully, an eventual post-mortem is gonna be juicy and then we can critique all we want.
PatrolXalmost 5 years ago
Verified Twitter accounts can no longer Tweet while incident is being dealt with.
exceptalmost 5 years ago
The attacker must have added some high level access, for it to be still ongoing.
stockholmalmost 5 years ago
Twitter should just ban all Btc address posting momentarily until this is solved
Acrobatic_Roadalmost 5 years ago
What could have been the best prank of 2020 wasted on a bitcoin scam. If it were me, I&#x27;d try to start a war or two as the ayatollah, or maybe make some unplanned celebrity trump endorsements. Wasted potential.
WarOnPrivacyalmost 5 years ago
and Obama <a href="https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;BarackObama&#x2F;status&#x2F;1283515490653147139</a>
justinzollarsalmost 5 years ago
<a href="https:&#x2F;&#x2F;twitter.com&#x2F;NorthmanTrader&#x2F;status&#x2F;1283516339768918017" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;NorthmanTrader&#x2F;status&#x2F;128351633976891801...</a>
PatrolXalmost 5 years ago
Expect POTUS to go to DEFCON 1 and seize control of Twitter any second now.
dansoalmost 5 years ago
&gt; <i>At least some of the compromised accounts have multi-factor authentication enabled, including CoinDesk&#x27;s.</i><p>Interesting. I wonder if it was a SMS hack, and if not, then a new kind of vulnerability?
评论 #23851691 未加载
评论 #23851872 未加载
VWWHFSfQalmost 5 years ago
The hackers made more profit in 5 minutes than Twitter has in 10 years
dsr12almost 5 years ago
Twitter support tweeted: &quot;We are aware of a security incident impacting accounts on Twitter. We are investigating and taking steps to fix it. We will update everyone shortly.&quot;
beezischillinalmost 5 years ago
The screenshots seem to show accounts shadow-banned, something Twitter denied doing for years... I am referring to those labels showing banned from search, etc. Seems interesting.
monokhalmost 5 years ago
Some reports that this was related to compromised OAuth tokens. How would someone know and what is the source of the compromise? A third party app that all of these accounts use?
aliabdalmost 5 years ago
Do we think scammers also have access to the hacked account’s DMs?
lanevorockzalmost 5 years ago
It&#x27;s really strange to claim it was &quot;simultaneous&quot; account hacking instead of Twitter being hacked. I guess all journalism today has 50% opinion in the middle.
drummeralmost 5 years ago
These hackers are clearly amateurs. If you&#x27;re going to post crypto scams on hijacked Twitter accounts you can&#x27;t NOT include John McAfee&#x27;s account. Seriously.
yazinsaialmost 5 years ago
Imagine buying puts on TSLA and tweeting this from @elonmusk:<p>&gt; Stepping down from TSLA effectively immediately. Focusing 100% on SpaceX. Life&#x27;s short.<p>This could easily be worth $100m&#x27;s
solinentalmost 5 years ago
Everyone here is suggesting a monetary motive. Maybe there&#x27;s a political motive--someone who really hates Twitter or serves to benefit if Twitter suffers.
评论 #23854230 未加载
评论 #23854213 未加载
ericmayalmost 5 years ago
I also got an email verification request for an old Reddit account I didn’t even remember having. Take a look there too. It happened at the same time.
pier25almost 5 years ago
Barack Obama too: <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;KGTEQNt" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;KGTEQNt</a>
zone411almost 5 years ago
I wonder what the automated trading bots tracking these accounts did.<p>Will Twitter get sued by the people who fell for this scam? By the people who got hacked?
borplkalmost 5 years ago
This is likely due to third-party social media account management software getting hacked. And they probably used compromised API tokens.
totaldude87almost 5 years ago
How many DM’s would have been read ... could it be for black mailing? Anyways would love to see a postmortem ( if Twitter shares such)
评论 #23854398 未加载
zellyalmost 5 years ago
Work from home wouldn&#x27;t backfire, they said.
pier25almost 5 years ago
Apple too: <a href="https:&#x2F;&#x2F;imgur.com&#x2F;ZvPshMX.jpg" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;ZvPshMX.jpg</a>
hoschiczalmost 5 years ago
Really surprised by this. I suspect a system-level 2FA hack or a bug exploit, all these people woudln&#x27;t fall for phishing
kartayyaralmost 5 years ago
Jeff Bezos too.<p><a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Zd668ao" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Zd668ao</a>
XCSmealmost 5 years ago
Maybe it&#x27;s Dr DisRespect&#x27;s revenge.
rumorialmost 5 years ago
All type of accounts are posting the same message. Out of curiosity I just deactivated mine, let&#x27;s see what happens.
WarOnPrivacyalmost 5 years ago
Joe Biden&#x27;s turn <a href="https:&#x2F;&#x2F;twitter.com&#x2F;JoeBiden&#x2F;status&#x2F;1283512317846659073" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;JoeBiden&#x2F;status&#x2F;1283512317846659073</a>
评论 #23852238 未加载
AzzieElbabalmost 5 years ago
Can&#x27;t help imagining twitter engineers holding the last line of defense between the hackers and trumps account.
Firebrandalmost 5 years ago
It appears Twitter has now prevented verified accounts from posting. Us schlubs can now run the asylum for a while.
coronadisasteralmost 5 years ago
dang, if you would collapse all threads by default and only show&#x2F;load top level comments, you probably would not even need this performance workaround. On the first page of your performance workaround, there was only 4 top-level comments... probably less than 100 total, I would guess (for most posts).
partisanalmost 5 years ago
One possibility is that a twitter employee was blackmailed with some personal information and forced to do this.
sleepyshiftalmost 5 years ago
In an attempt to mitigate the damage, Twitter appears to have blocked verified accounts from sending tweets.
sleepyshiftalmost 5 years ago
I wonder whether this is just write-only, or if they&#x27;ve been able to read private data (like DMs) too.
jf-almost 5 years ago
This is nuts, Twitter is totally compromised and they haven’t pulled the plug. Not confidence inspiring.
totonyalmost 5 years ago
All in all that looks like a poorly thought out attack. So much more could&#x27;ve been done than cryptoscam.<p>Considering execution, it may be that this is some API 0day which does not show (or make it hard to guess) which account messages are being posted from. How else would you explain neutral messages for all account when you could&#x27;ve personalised it per account to maximize efficiency.
WarOnPrivacyalmost 5 years ago
I love the internet so much right now.
thatwasunusualalmost 5 years ago
&gt; With so many accounts compromised, the hackers might actually have full access to Twitter&#x27;s backend.<p>This.
mikewhyalmost 5 years ago
Headline seems pretty editorialized.
评论 #23852433 未加载
awakealmost 5 years ago
Looks like hackers got approx 60K. Anybody know how that compares to bug bounties at Twitter?
评论 #23854447 未加载
fortran77almost 5 years ago
This doesn&#x27;t make me feel any better about Bitcoin as a platform&#x2F;product.
challengealmost 5 years ago
rumors say the hacker got access to an internal (used by employees) admin panel...
gmngmn22almost 5 years ago
I guess an employee screwing up thing is easier to imagine now with everybody wfh
GrumpyNlalmost 5 years ago
Is this the beginning of the end for twitter? Tweets can not be trusted anymore.
magma17almost 5 years ago
Curiously, Elon&#x27;s btc address is different from the others. Nice try, elon.
1-6almost 5 years ago
Did someone gain access to the Twitter building in SF while everyone was away?
plucalmost 5 years ago
They didn&#x27;t hack anything, the access was given to them by an insider.
young_unixeralmost 5 years ago
If they made a movie about how these guys did it, I would totally watch it.
dewelleralmost 5 years ago
These are already removed. Does anyone have a screenshot or other archive?
caretak3ralmost 5 years ago
Hahah looks like it&#x27;s getting closer: OAuth account takeover? <a href="https:&#x2F;&#x2F;twitter.com&#x2F;LiveOverflow&#x2F;status&#x2F;1283511782380908545" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;LiveOverflow&#x2F;status&#x2F;1283511782380908545</a>
scrosealmost 5 years ago
I wonder what a bug bounty for something like this would have paid out.
Silly_Sprayalmost 5 years ago
The scammer has got $100k and counting in less than 30mins. WOW 2020.
webXLalmost 5 years ago
$113k scammed and counting.... Why is twitter still in write mode??
pfarnsworthalmost 5 years ago
How did they possibly steal Elon Musk&#x27;s Twitter account? We need a post-mortem on this because if he can be phished, then we need to know how, and if it was some internal hack then I also need to know how. That&#x27;s extremely scary!
freakynitalmost 5 years ago
This seems more and more like a diversion for something else.
qeternityalmost 5 years ago
A lot of people (rightly) pointing out that the actual exploit payload here is a horribly inefficient way to monetize such awesome power. Some of the replies that influencing regulated markets would be traceable...sure, but trillions of dollars flow through these markets each and every day. A decently large options position accumulated over days wouldn&#x27;t raise any red flags, and one tweet about the Fed raising rates on the back of strong employment + vaccine hope would have sent markets into a tailspin. The reality is that it would be much more difficult to identify bad actors than it is with public crypto addresses. And your money is clean at that point, part of the US financial system (or other tier 1 banking system).
评论 #23852552 未加载
cookie_monstaalmost 5 years ago
Does this mean that Twitter is now not to be trusted?
jonny_ehalmost 5 years ago
Twitter right now: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;i&#x2F;status&#x2F;1283517347894980610" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;i&#x2F;status&#x2F;1283517347894980610</a>
qgadrianalmost 5 years ago
Did the hackers remove all tweets from Apple? Wtf
评论 #23852657 未加载
评论 #23851991 未加载
teknopurgealmost 5 years ago
Exchanges should[can] blacklist the address.
评论 #23852220 未加载
Scoundrelleralmost 5 years ago
Interesting how @Apple currently displays zero tweets at all.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;Apple" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Apple</a>
swalshalmost 5 years ago
Oh finally, some real news about hackers.
jacquesmalmost 5 years ago
Whoever did this is going to have a serious price on their heads. I doubt the pay off is worth it unless they are a state actor flexing their muscle.
justinzollarsalmost 5 years ago
Instead of putting so much engineering time into pushing a political agenda, twitter should focus on security and identity improvements.
abigger87almost 5 years ago
<a href="https:&#x2F;&#x2F;gifyu.com&#x2F;image&#x2F;QrnS" rel="nofollow">https:&#x2F;&#x2F;gifyu.com&#x2F;image&#x2F;QrnS</a>
bishalbalmost 5 years ago
So which ones of you did this? ;)
anigbrowlalmost 5 years ago
I&#x27;ve seen the groundwork for this over the last 6-8 weeks, with &#x27;people&#x27; (questionable-looking accounts) retweeting screenshots of similar-looking tweets purporting to be from Elon Musk, and other similarly fishy accounts going &#x27;wow it really works&#x27; or the like. I noticed them showing up consistently in replies to Trump tweets, probably just because they get tons of engagement.
评论 #23855126 未加载
nathancahillalmost 5 years ago
Apple and Kanye West too.
abetteramericaalmost 5 years ago
So, does no one think this was China doing a &#x27;we can do what we want when we want&#x27; as a response to Trump&#x27;s executive order the day before this happened? And if it is, would they be honest about the cause since that would require a response and likely an escalation?
justiczalmost 5 years ago
Just imagine if Trump’s account were hacked to indicate that the US is launching a missile towards North Korea. Or maybe a message to encourage some kind of armed uprising in the US.<p>Hacking the right Twitter account could easily have massive life-and-death consequences. Isn’t that terrifying?
nickysielickialmost 5 years ago
I find it fascinating that they didn&#x27;t target @POTUS&#x2F;@realDonaldTrump. I wonder if there are specific mechanisms in place to protect accounts that could, y&#x27;know, start WW3, that aren&#x27;t rolled out to other blue checkmark accounts.
downshunalmost 5 years ago
A clear use case of Blockchain for the cryptocurrency detractors \s
abvdaskeralmost 5 years ago
I don&#x27;t think anyone appreciates how scary this is. A simple BTC scam or even market manipulation is one thing. Can you imagine the mass panic if there were one sombre tweet from Trump&#x27;s account about a nuclear strike?
codesternewsalmost 5 years ago
Security is myth
babuloseoalmost 5 years ago
Get the popcorn!
stevefan1999almost 5 years ago
#cancelTwitter
koolbaalmost 5 years ago
Did they send one out from Trump as well? Imagine the mayhem if they send out a notice that he’s resigning or that he is launching nukes.
the_svd_doctoralmost 5 years ago
Are very high profile accounts (like Trump) more secure than a usual password + 2FA, somehow ?<p>EDIT: Not that it would matter here. Just curious.
评论 #23853678 未加载
ipythonalmost 5 years ago
How is this different from the persistent “Elon Musk” btc giveaway posts that find their way onto every one of Trump’s tweets?
评论 #23855133 未加载
londons_explorealmost 5 years ago
Notable that Trump is <i>not</i> impacted.<p>If you had backdoor access to any Twitter account, why on earth wouldn&#x27;t you tweet as Trump?
评论 #23853329 未加载
challengealmost 5 years ago
also all @apple tweets have been deleted lol the hacker already got 6 BTC! this is crazy.
dynamite-readyalmost 5 years ago
Wait... So the hackers were able to target Joe Biden&#x27;s account, Barrack Obama&#x27;s, but not Trump&#x27;s?<p>That is very odd.
genidoialmost 5 years ago
Chilling to imagine a tweet from Trump declaring a nuclear strike has been launched against China.
leeoniyaalmost 5 years ago
hard to feel sorry for anyone who falls for this.
forsakenalmost 5 years ago
No Trump?
评论 #23853629 未加载
评论 #23852215 未加载
ycombonatoralmost 5 years ago
Related <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23853786" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23853786</a>
staycoolboyalmost 5 years ago
I really HOPE the details of this hack become public, because this is huge. (I can already hear celebs who say dubious things trying to claim they were hacked.)
megadethalmost 5 years ago
Top crypto currency accounts compromised
paul_falmost 5 years ago
This entire thread and not one mention of 4Chan. Why isn&#x27;t this simply an insider with a few friends doing this for fun?
ISLalmost 5 years ago
This must be a shot over someone&#x27;s bow.<p>Edit: Or a trading play? That would have taken place while the markets were open, though. TWTR after-hours trading is off 3% on the news.
mindfreezealmost 5 years ago
All Apple Tweets are now deleted<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;apple" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;apple</a> and now one scam alone <a href="https:&#x2F;&#x2F;twitter.com&#x2F;Apple&#x2F;status&#x2F;1283506278707408900" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Apple&#x2F;status&#x2F;1283506278707408900</a>
评论 #23853499 未加载
caetris1almost 5 years ago
I&#x27;ve never heard of Hacker News censoring comments that do not abuse the site guidelines, with rational opinions. This comment thread is being heavily censored. This fundamentally abuses the trust that users have put into this site.
评论 #23854969 未加载