Jump to content

Twitter Cypto Hack (Ongoing right now)

ESPImperium

Its a hack, they have found a venerability at the heart of Twitters God mode that can control all Tweets/Accounts.

Intel i9 9900X | EVGA X299 Micro 2 | Asus GTX 1070 Strix Gaming 8GB | G.Skill 32GB DDR4 (4X8GB) 3200 | EVGA 280mm CLC

Seasonic 1300w Focus Gold | Samsung 500GB 970 EVO

WD Black 2TB/WD Black 1TB (X2)/Seagate 4TB Ironwolf/Crucial 1TB P1/Crucial MX500 500GB/Samsung 1TB QVO

Phanteks Entho Evolve MATX

Samsung LS29E790C 29 Inch Monitor | LG 24UD58 24 inch 4K UHD

Coolermaster Master Keys Pro RGB (Cherry MX Brown)

Logitech G700s

Razer Leviathan

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, ESPImperium said:

Its a hack, they have found a venerability at the heart of Twitters God mode that can control all Tweets/Accounts.

Source? or are you an employee or something? 

 

This is kinda interesting

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

i didnt know elon musk, bill gates, and jeff bezos all use the same bitcoin wallet

Link to comment
Share on other sites

Link to post
Share on other sites

This is shaping up to be the biggest security compromise in Twitter ever. Or perhaps this is another case like the self-retweeting tweet, where the problem is in some app that interfaces with Twitter being used by all of these people who got hacked. I really hope we get info on how this happened once it's fixed.

¯\_(ツ)_/¯

 

 

Desktop:

Intel Core i7-11700K | Noctua NH-D15S chromax.black | ASUS ROG Strix Z590-E Gaming WiFi  | 32 GB G.SKILL TridentZ 3200 MHz | ASUS TUF Gaming RTX 3080 | 1TB Samsung 980 Pro M.2 PCIe 4.0 SSD | 2TB WD Blue M.2 SATA SSD | Seasonic Focus GX-850 Fractal Design Meshify C Windows 10 Pro

 

Laptop:

HP Omen 15 | AMD Ryzen 7 5800H | 16 GB 3200 MHz | Nvidia RTX 3060 | 1 TB WD Black PCIe 3.0 SSD | 512 GB Micron PCIe 3.0 SSD | Windows 11

Link to comment
Share on other sites

Link to post
Share on other sites

Also @ESPImperium you spelled crypto wrong. 

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, BobVonBob said:

This is shaping up to be the biggest security compromise in Twitter ever. Or perhaps this is another case like the self-retweeting tweet, where the problem is in some app that interfaces with twitter being used by all of these people who got hacked. I really hope we get info on how this happened once it's fixed.

It's probably not as complicated as people are making it out to be. One of three possiblities come to mind:

a) It's an inside job, eg someone inside was hacked and/or a twitter employee was partially responsible

b) Twitter API hack, likely something like tweetdeck that is managed by a social media manager got hacked

c) Twitter API hack 2, maybe there's a way to post as someone else that was discovered and there's no actual "hack" involved on the accounts, just the API endpoint wasn't verifying that they were who they said they were.

 

Either way B and C are easily taken care of since all someone had to do was look for every tweet with the same message, like any other spam. A would be something that requires more involvement.

 

Chances are that anyone stupid enough to send money was probably someone that was following MrBeast rather than Apple or Elon, as this is very much his style of doing things (giving money away.)

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Kisai said:

It's probably not as complicated as people are making it out to be. One of three possiblities come to mind:

a) It's an inside job, eg someone inside was hacked and/or a twitter employee was partially responsible

b) Twitter API hack, likely something like tweetdeck that is managed by a social media manager got hacked

c) Twitter API hack 2, maybe there's a way to post as someone else that was discovered and there's no actual "hack" involved on the accounts, just the API endpoint wasn't verifying that they were who they said they were.

 

Either way B and C are easily taken care of since all someone had to do was look for every tweet with the same message, like any other spam. A would be something that requires more involvement.

 

Chances are that anyone stupid enough to send money was probably someone that was following MrBeast rather than Apple or Elon, as this is very much his style of doing things (giving money away.)

I wasn't saying it was complicated, just musing on what could have happened. Given all the accounts compromised it's unlikely it's actual account hacking, so there's a vulnerability either in Twitter or in something connected to it that allows either tweeting as others or compromising an account nearly instantly. An outlandish but possible explanation, it might even be a password manager hack. At this point we only see the symptoms, not the cause, so it's difficult to determine with any degree of certainty what's happening here.

 

Also, there was over $100,000 USD in bitcoin sent to that wallet before Mr Beast's account was compromised, so it's not just his fans getting screwed.

¯\_(ツ)_/¯

 

 

Desktop:

Intel Core i7-11700K | Noctua NH-D15S chromax.black | ASUS ROG Strix Z590-E Gaming WiFi  | 32 GB G.SKILL TridentZ 3200 MHz | ASUS TUF Gaming RTX 3080 | 1TB Samsung 980 Pro M.2 PCIe 4.0 SSD | 2TB WD Blue M.2 SATA SSD | Seasonic Focus GX-850 Fractal Design Meshify C Windows 10 Pro

 

Laptop:

HP Omen 15 | AMD Ryzen 7 5800H | 16 GB 3200 MHz | Nvidia RTX 3060 | 1 TB WD Black PCIe 3.0 SSD | 512 GB Micron PCIe 3.0 SSD | Windows 11

Link to comment
Share on other sites

Link to post
Share on other sites

It's ridiculous that they were still able to post as recently as a few minutes ago. 

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

Hey at least we all get a break from tiresome blue-checks talking down at us for a while...

Link to comment
Share on other sites

Link to post
Share on other sites

40 minutes ago, piratemonkey said:

Source? or are you an employee or something? 

 

This is kinda interesting

No source, just what someone had as a Theory.

27 minutes ago, piratemonkey said:

Also @ESPImperium you spelled crypto wrong. 

Fixed.

 

 

All verified accounts on the platform have been temporarily stopped from tweeting right now.

 

Its as if someone somewhere is trying to send a message, with all the military buildups, trade wars and tech wars going on at the moment. That message is “We still own your asses” or something to that degree.

Intel i9 9900X | EVGA X299 Micro 2 | Asus GTX 1070 Strix Gaming 8GB | G.Skill 32GB DDR4 (4X8GB) 3200 | EVGA 280mm CLC

Seasonic 1300w Focus Gold | Samsung 500GB 970 EVO

WD Black 2TB/WD Black 1TB (X2)/Seagate 4TB Ironwolf/Crucial 1TB P1/Crucial MX500 500GB/Samsung 1TB QVO

Phanteks Entho Evolve MATX

Samsung LS29E790C 29 Inch Monitor | LG 24UD58 24 inch 4K UHD

Coolermaster Master Keys Pro RGB (Cherry MX Brown)

Logitech G700s

Razer Leviathan

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, ESPImperium said:

Its as if someone somewhere is trying to send a message, with all the military buildups, trade wars and tech wars going on at the moment. That message is “We still own your asses” or something to that degree.

I doubt the motivations are nearly that grandiose. Some hacker found an exploit and wanted to make a quick buck. "Send money to this bitcoin wallet" isn't exactly the message I'd expect from someone trying to create global tension.

¯\_(ツ)_/¯

 

 

Desktop:

Intel Core i7-11700K | Noctua NH-D15S chromax.black | ASUS ROG Strix Z590-E Gaming WiFi  | 32 GB G.SKILL TridentZ 3200 MHz | ASUS TUF Gaming RTX 3080 | 1TB Samsung 980 Pro M.2 PCIe 4.0 SSD | 2TB WD Blue M.2 SATA SSD | Seasonic Focus GX-850 Fractal Design Meshify C Windows 10 Pro

 

Laptop:

HP Omen 15 | AMD Ryzen 7 5800H | 16 GB 3200 MHz | Nvidia RTX 3060 | 1 TB WD Black PCIe 3.0 SSD | 512 GB Micron PCIe 3.0 SSD | Windows 11

Link to comment
Share on other sites

Link to post
Share on other sites

24 minutes ago, ESPImperium said:

Fixed.

...Forgot the r in crypto... sorry

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, BobVonBob said:

I doubt the motivations are nearly that grandiose. Some hacker found an exploit and wanted to make a quick buck. "Send money to this bitcoin wallet" isn't exactly the message I'd expect from someone trying to create global tension.

Apparently all verified accounts were disabled from posting within the last hour, so presumably they're investigating this now.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Kisai said:

c) Twitter API hack 2, maybe there's a way to post as someone else that was discovered and there's no actual "hack" involved on the accounts, just the API endpoint wasn't verifying that they were who they said they were.

Thats my guess. That or there is a log in exploit thats allowing someone to log in without use of a password.

Link to comment
Share on other sites

Link to post
Share on other sites

PSA: you should enable two-factor authentication if you haven't

 

My account on  another forum website just got hacked, I'm completely locked out of it. If I had 2FA on then my account wouldn't have been hacked even if the attacker had my password and everything.

 

2FA can literally be a lifesaver and it can prevent a lot of incidents like this from happening

 

 

Twitter has a 2FA option, so please use it

 

Screenshot_20200716-083243_Twitter.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, realpetertdm said:

PSA: you should enable two-factor authentication if you haven't

 

funnily? enough, the official ripple twitter account got hacked, and they confirmed they had 2fa on. I think it was some bug in an api

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, piratemonkey said:

funnily? enough, the official ripple twitter account got hacked, and they confirmed they had 2fa on. I think it was some bug in an api

If that's true then yeah it's probably something wrong with the software like an exploit or a bug.

 

Still, turn 2FA on when possible, even if it's a bit annoying

Link to comment
Share on other sites

Link to post
Share on other sites

Update: Twitter is saying that this is the result of one of the employees accounts getting hacked

 

Source: https://www.cnet.com/news/twitter-says-hackers-got-access-to-internal-tools-for-hijacking-spree/

I am far from an expert in this so please correct me if I’m wrong.

Quote or tag me so I can see your response

 

PSU Tier List

Motherboard Tier List

Graphics Card Cooling Tier List

CPU Cooler Tier List

SSD Tier List

 

PARROT GANG

Mentioned in 7/10/20 WAN Show

Mentioned in 7/15/20 Techlinked

Mentioned in 7/17/20 Techlinked

Mentioned in 7/31/20 WAN Show

Mentioned in 7/31/20 Techlinked

Mentioned in 8/3/20 Techlinked

Mentioned twice in 8/5/20 Techlinked

Mentioned twice in 8/7/20 Techlinked

Mentioned in 8/12/20 Techlinked

Mentioned in 8/19/20 Techlinked

Link to comment
Share on other sites

Link to post
Share on other sites

anyone that falls for something like this is a moron

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, gabrielcarvfer said:

It was just the cherry on top. Can you imagine what kind of ransom the hackers can get with access to all the private messages they probably collected?

i dont think they got access to the actual accounts, just the ability to make posts on behalf of other people

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

34 minutes ago, zeusthemoose said:

Update: Twitter is saying that this is the result of one of the employees accounts getting hacked

 

Source: https://www.cnet.com/news/twitter-says-hackers-got-access-to-internal-tools-for-hijacking-spree/

 

https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos

 

So... basically it was A.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Arika S said:

i dont think they got access to the actual accounts, just the ability to make posts on behalf of other people

I think (through the Twitter employee tool/portal) they could change the email of an account and reset the password giving access to the whole account.

 

Given that Twitter verification works (I think) by tweeting at an employee, I would think that a tool to help with account management at one point wouldn't be removed. 

 

This is just speculation, I doubt that Twitter would ever release that kind of info.

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, gloop said:

I don't mean to be rude, but how dumb do you have to be to fall for something like this?

Lots of people, the human brain evolved with reward mechanisms for survival, if you trip the reward or fear mechanism,  the brain typical overrides rational thought (which is too slow for survival purposes).  That is why we have so many conspiracy theories, people thinking they know better than the medical fraternity in general, people who buy into pyramid schemes and successful con artists like this.  

 

There is also substantial evidence to suggest that intelligence has little to do with how likely you are to fall for this.  We (being tech enthusiasts) aren't general victims because most of us have worked with victims or at least seen these scams many times before on the internet. We have become aware of the tactics and measures taken and have pre-established rules (like do not send money to strangers) to deal with it.  The average person who falls for these scams do not have the same forethought or experience.

 

 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×