Hacker breaches 15 X accounts, nets $500K boosting bogus memecoins: ZachXBT

As a seasoned researcher and blockchain investigator who has seen my fair share of cybercrime, this latest memecoin phishing scam is nothing short of a masterclass in social engineering. The perpetrator’s ability to compromise 15 high-profile X accounts, netting over half a million dollars, is a stark reminder that no one is immune to these attacks.

It appears that a hacker has swindled approximately half a million dollars in the past month by tricking unsuspecting users through memecoin phishing schemes on 15 hacked X account, as reported by blockchain analyst ZachXBT.

In a December 24 post, ZachXBT clarified that the wrongdoer falsely represented himself as part of Team X and distributed fraudulent copyright violation warnings. The intention was to instill a sense of urgency among social media users, causing them to unknowingly click on deceptive phishing links.

In essence, the unsuspecting victims were led to a sham website where they unwittingly reset the passwords for their X accounts as well as their two-factor authentications (2FA).

Using the data, the offender managed to seize control over fifteen accounts and spread memecoin fraud schemes through them, amassing approximately half a million dollars in total.

ZachXBT pointed out that the majority of the hacked X accounts were centered around cryptocurrencies and they encompassed entities such as Kick, Cursor, The Arena, Brett, and Alex Blania in this context.

In each instance of memecoin fraud, all account takeovers were linked through the use of six specific deployer addresses. The perpetrator tried to hide the origin of the funds by moving them across the Solana and Ethereum networks, as stated by ZachXBT.

The blockchain sleuth recommended X users limit email address reuse between services and implement 2FA on “important accounts wherever possible.”

The earliest recorded event took place on November 26, involving the user X from RuneMine, while the most recent incident happened on December 24, referred to as Kick.

A significant number of these X accounts boast a substantial following, exceeding 200,000 users, who are primarily enthusiasts of meme coins, seeking the next popular trend.

In many cases, meme coin phishing schemes are labeled as “Incoming Messages” or “Transmissions,” then they include an announcement about a new token and provide the contract address.

brett hacked? $BRETT @BasedBrett

— KrakenGFX (@_KrakenGFX) December 2, 2024

Certain affected accounts associated with the cross-chain scalability platform Neutron, like some others, have owned up to the reported occurrence.

Scam artists involved with cryptocurrencies might attempt to recover their losses during the upcoming holidays, as reported phishing incidents and associated financial losses decreased by 53% from October to November, amounting to approximately $9.3 million.

In the year 2024, approximately $2.2 billion was taken illicitly from 303 significant crypto heists, as revealed by a report from blockchain investigation company Chainalysis within the last few weeks.

The firm said it marked a 21% year-on-year increase, with centralized services among the hardest hit.

Read More

2024-12-25 04:34