Twitter Account Hack: Ethereum's Vitalik Buterin Falls Victim to SIM-Swap Attack
In a candid revelation, Ethereum's Co-Founder Vitalik Buterin disclosed that the recent hack of his Twitter account, known as X, was the result of a SIM-swap attack. Speaking on the decentralized social media platform, F...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
In a candid revelation, Ethereum's Co-Founder Vitalik Buterin disclosed that the recent hack of his Twitter account, known as X, was the result of a SIM-swap attack. Speaking on the decentralized social media platform, Farcaster on September 12, Buterin shed light on the incident and offered some valuable lessons learned.
SIM-Swap Attacks on the Rise: Telecom Companies under Scrutiny
A SIM-swap attack, also known as simjacking, is a tactic employed by hackers to seize control of a victim's mobile phone number. Once in possession of the phone number, scammers can exploit two-factor authentication (2FA) to access social media accounts, banking services, and cryptocurrency holdings.
Buterin's revelation serves as a stark reminder of the evolving threats in the digital age and the importance of safeguarding personal information and online accounts from potential vulnerabilities. It additionally calls for increased vigilance among both individuals and service providers to fortify security measures against these types of cyberattacks.
The Vulnerability of Phone Numbers: Password Reset for X Accounts
Buterin explained that the attacker executed a SIM-swap attack by socially engineering T-Mobile, the mobile service provider. This manipulation allowed the hacker to gain control of Buterin's phone number, which subsequently led to compromising his X account.
He emphasized the inherent vulnerability of using a phone number for password recovery on social media platforms, even when it's not utilized for two-factor authentication (2FA). Buterin's experience underscored the importance of users taking proactive measures to protect their online accounts.
"A phone number is sufficient to password reset a Twitter account even if not used as 2FA," Buterin warned, adding that users have the option to "completely remove [a] phone from Twitter." This revelation highlights a critical security flaw that many may not have been aware of.
The hacking incident, which transpired on September 9, involved scammers taking control of Buterin's Twitter account and conducting a fraudulent NFT giveaway. Users were prompted to click on a malicious link, resulting in collective losses exceeding $691,000.
T-Mobile Faces Lawsuit over SIM-Swap Attack Leading to $450,000 Crypto Theft
Notably, this is not the first time that T-Mobile has been associated with such attacks. Finance Magnates reported earlier, that a victim of cryptocurrency theft resulting from a SIM-swap attack has taken legal action against U.S. cell phone carrier T-Mobile, alleging negligence in preventing such scams. According to court documents filed recently, Calvin Cheng, the plaintiff, suffered the loss of 15 Bitcoins valued at over $450,000 due to the attack.
The lawsuit has accused T-Mobile of systemic and repeated failure to safeguard its customers' sensitive personal and financial information against foreseeable attempts to obtain this data illegally. Cheng's case involved a perpetrator impersonating Brandon Buchanan, the Co-Founder of investment fund Iterative Capital, who had also fallen victim to a SIM-swap attack.
The lawsuit highlights that SIM-swap attacks are a well-known method used to gain access to victims' phones, yet T-Mobile allegedly lacked security measures to prevent such incidents. Notably, AT&T, another major U.S. cell phone service provider, has faced similar legal challenges over SIM-swap attacks, and the lawsuit against T-Mobile reflects a growing concern over the responsibility of telecom companies in preventing these increasingly prevalent cybercrimes.
This article was written by Tareq Sikder at www.financemagnates.com.Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Finance MagnatesRelated market context
French tax breach exposes nearly 678,000 people as crypto wrench attacks pile up
Crypto wrench attacks in France are on pace to make 2026 the worst year ever for violent crimes targeting crypto holders in the co...
Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Key Takeaways: Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to ap...
With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line
On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyer...
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...
SafePal Data Breach Exposes 39,798 Crypto Customers, Wallet Keys Remain Secure
Key Takeaways: About 39,798 users’ personal and purchase information were disclosed via a flaw in an order tracking plugin, accord...
Chainalysis says successful crypto extortions plummeted to 26% as attackers get sloppier
The decline in successful crypto extortions highlights the need for enhanced security measures as attackers adapt and financial lo...