financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Animoca Brands’ Exec Explains How His X Account Was Hacked Despite 2FA
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Animoca Brands’ Exec Explains How His X Account Was Hacked Despite 2FA
Dec 26, 2024 11:55 PM

Blockchain gaming giant Animoca Brands revealed that co-founder and chair Yat Sius X account was hacked, promoting a fraudulent token on Solanas Pump.fun platform.

The attackers impersonated Animoca and falsely announced the launch of a token. Blockchain investigator ZachXBT attributed the hack to a phishing scam that has recently targeted over 15 crypto-focused X accounts, ultimately stealing almost $500,000.

Fraudulent MOCA Token

Sius hacked account shared a link to a fake token called Animoca Brands (MOCA) on the Pump.fun platform, which bore the same name as both the company and its Mocaverse NFT collection. This fraudulent MOCA token was then traced back to the same address behind other fraudulent tokens, ZachXBT confirmed.

After being promoted on Sius account, the token briefly reached a peak value of almost $37,000, only to crash moments later to a market cap of just $5,735, as per data compiled by Birdeye. Currently, there are only 33 holders of the token.

ZachXBT had previously uncovered this sophisticated phishing scheme wherein phishing emails disguised as urgent messages from the X team often cited fabricated copyright issues and tricked victims into resetting their account credentials.

The scheme leveraged the credibility of crypto-related accounts with large audiences. A majority of those had more than 200,000 followers. Affected accounts included Kick, Cursor, The Arena, Brett, and Alex Blania. The first attack was on November 26, involving RuneMine, and the most recent occurred on December 24, affecting Kick, just before Sius.

2FA Not Enough to Secure Accounts

Siu explained that the hacker somehow obtained his password and used the account recovery page to bypass 2FA by submitting a request with a non-registered email address. He tested this process and noted a significant security gap: while the system triggered a login notification to the wrong email, the actual, registered email received no alerts regarding critical actions like a 2FA change request.

He said that this lack of notification could have prevented the hack. Siu also added that the hacker submitted a government-issued ID to bypass further security checks, a tactic he suspects was facilitated by phishing. He urged X to implement stronger notifications, particularly for sensitive changes like 2FA modifications, and recommended better verification measures to protect accounts.

Siu also warned that 2FA alone is not enough to secure an account and advised maintaining strong password hygiene, as attackers can bypass 2FA once they have access to the password.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Miners’ Bitcoin (BTC) Stash Dwindles to Levels Unseen Since Satoshi Era
Miners’ Bitcoin (BTC) Stash Dwindles to Levels Unseen Since Satoshi Era
Jun 4, 2024
The supply of bitcoin held by miners has dwindled to levels not seen in over 14 years. This massive decline in miner reserves comes at a time when the broader cryptocurrency market is witnessing a surge in institutional interest and growing mainstream adoption. Bitcoin Miner Reserves Hit 14-Year Low According to on-chain analysis firm CryptoQuants latest analysis, the last time...
Polkadot (DOT) Ecosystem Recap: The Recent Advancements
Polkadot (DOT) Ecosystem Recap: The Recent Advancements
Jun 4, 2024
TL;DR Polkadot Blockchain Academy launched its fifth cohort in Singapore to nurture developer talent with 184 lecture hours and 18 experienced instructors. Polkadot recently introduced Asynchronous Backing for better block validation and partnered with Founder Institute for a Web3 cohort. Despite those advancements, DOTs price remains steady at around $7, with mixed future predictions. The Latest Update According to a...
Bitcoin (BTC), Ethereum (ETH) – Technical Outlooks
Bitcoin (BTC), Ethereum (ETH) – Technical Outlooks
Jun 4, 2024
Bitcoin (BTC), Ethereum (ETH) - Prices, Charts, and Analysis: BTC/USD - A break above short-term resistance may lead to a longer-term move higher.Ethereum – The technical setup is looking increasingly positive. Recommended by Nick Cawley Get Your Free Bitcoin Forecast Bitcoin has been treading water for the last three weeks with little to suggest either a move higher or lower....
Is Dogecoin Ready to Reach the $1 Milestone? Analysts With Interesting DOGE Price Predictions
Is Dogecoin Ready to Reach the $1 Milestone? Analysts With Interesting DOGE Price Predictions
Jun 4, 2024
TL;DR Despite Dogecoins recent decline to around $0.15, numerous analysts foresee a significant price increase, with one predicting a 7x rise to over $1. Ali Martinez notes a key resistance at $0.166-$0.171, suggesting a potential rise to $0.32 if overcome. DOGE Bull Run in the Making? The largest meme coin in terms of market capitalization Dogecoin (DOGE) experienced a significant...
Copyright 2023-2026 - www.financetom.com All Rights Reserved