BPOI Banner
Centralized Exchanges Reclaimed by Hackers as Ransomware Payments Soar in 2024: Chainalysis Centralized Exchanges Reclaimed by Hackers as Ransomware Payments Soar in 2024: Chainalysis

Animoca Brands’ Exec Explains How His X Account Was Hacked Despite 2FA

Blockchain gaming giant Animoca Brands revealed that co-founder and chair Yat Siu’s X account was hacked, promoting a fraudulent token on Solana’s Pump.fun platform.

The attackers impersonated Animoca and falsely announced the launch of a token. Blockchain investigator ZachXBT attributed the hack to a phishing scam that has recently targeted over 15 crypto-focused X accounts, ultimately stealing almost $500,000.

Fraudulent ‘MOCA’ Token

Siu’s hacked account shared a link to a fake token called Animoca Brands (MOCA) on the Pump.fun platform, which bore the same name as both the company and its Mocaverse NFT collection. This fraudulent MOCA token was then traced back to the same address behind other fraudulent tokens, ZachXBT confirmed.

After being promoted on Siu’s account, the token briefly reached a peak value of almost $37,000, only to crash moments later to a market cap of just $5,735, as per data compiled by Birdeye. Currently, there are only 33 holders of the token.

ZachXBT had previously uncovered this sophisticated phishing scheme wherein phishing emails disguised as urgent messages from the X team often cited fabricated copyright issues and tricked victims into resetting their account credentials.

The scheme leveraged the credibility of crypto-related accounts with large audiences. A majority of those had more than 200,000 followers. Affected accounts included Kick, Cursor, The Arena, Brett, and Alex Blania. The first attack was on November 26, involving RuneMine, and the most recent occurred on December 24, affecting Kick, just before Siu’s.

2FA “Not Enough” to Secure Accounts

Siu explained that the hacker somehow obtained his password and used the account recovery page to bypass 2FA by submitting a request with a non-registered email address. He tested this process and noted a significant security gap: while the system triggered a login notification to the wrong email, the actual, registered email received no alerts regarding critical actions like a 2FA change request.

He said that this lack of notification could have prevented the hack. Siu also added that the hacker submitted a government-issued ID to bypass further security checks, a tactic he suspects was facilitated by phishing. He urged X to implement stronger notifications, particularly for sensitive changes like 2FA modifications, and recommended better verification measures to protect accounts.

Siu also warned that 2FA alone is not enough to secure an account and advised maintaining strong password hygiene, as attackers can bypass 2FA once they have access to the password.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Chayanika Deka

https://cryptopotato.com/animoca-brandss-exec-explains-how-his-x-account-was-hacked-despite-2fa/

2024-12-27 07:35:29

bitcoin
Bitcoin (BTC) $ 98,412.37 0.07%
ethereum
Ethereum (ETH) $ 3,661.58 1.24%
xrp
XRP (XRP) $ 2.43 1.09%
tether
Tether (USDT) $ 1.00 0.05%
solana
Solana (SOL) $ 216.92 0.06%
bnb
BNB (BNB) $ 714.07 0.03%
dogecoin
Dogecoin (DOGE) $ 0.395844 3.10%
usd-coin
USDC (USDC) $ 1.00 0.03%
cardano
Cardano (ADA) $ 1.07 2.21%
staked-ether
Lido Staked Ether (STETH) $ 3,656.18 1.15%
tron
TRON (TRX) $ 0.2699 0.21%
avalanche-2
Avalanche (AVAX) $ 42.80 2.03%
sui
Sui (SUI) $ 5.32 8.74%
wrapped-steth
Wrapped stETH (WSTETH) $ 4,348.77 1.15%
chainlink
Chainlink (LINK) $ 23.75 1.08%
the-open-network
Toncoin (TON) $ 5.74 1.13%
shiba-inu
Shiba Inu (SHIB) $ 0.000024 0.36%
stellar
Stellar (XLM) $ 0.452478 0.42%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 98,187.31 0.13%
hedera-hashgraph
Hedera (HBAR) $ 0.306802 2.36%
polkadot
Polkadot (DOT) $ 7.70 0.71%
weth
WETH (WETH) $ 3,655.92 1.06%
bitcoin-cash
Bitcoin Cash (BCH) $ 476.91 0.59%
uniswap
Uniswap (UNI) $ 15.31 0.68%
pepe
Pepe (PEPE) $ 0.000021 1.85%
leo-token
LEO Token (LEO) $ 9.14 0.33%
hyperliquid
Hyperliquid (HYPE) $ 25.41 6.64%
litecoin
Litecoin (LTC) $ 111.16 2.16%
bitget-token
Bitget Token (BGB) $ 6.02 3.65%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,862.43 1.06%
near
NEAR Protocol (NEAR) $ 5.81 0.27%
internet-computer
Internet Computer (ICP) $ 12.35 0.86%
ethena-usde
Ethena USDe (USDE) $ 0.99879 0.02%
usds
USDS (USDS) $ 1.00 0.02%
aptos
Aptos (APT) $ 9.99 2.10%
aave
Aave (AAVE) $ 353.34 0.50%
mantle
Mantle (MNT) $ 1.37 0.29%
bittensor
Bittensor (TAO) $ 562.08 1.47%
virtual-protocol
Virtuals Protocol (VIRTUAL) $ 4.50 4.07%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.525022 0.91%
crypto-com-chain
Cronos (CRO) $ 0.161981 0.89%
ethereum-classic
Ethereum Classic (ETC) $ 28.36 0.41%
render-token
Render (RENDER) $ 8.08 0.25%
vechain
VeChain (VET) $ 0.051027 3.81%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.49 0.07%
mantra-dao
MANTRA (OM) $ 3.96 0.91%
tokenize-xchange
Tokenize Xchange (TKX) $ 47.31 5.95%
arbitrum
Arbitrum (ARB) $ 0.897139 7.41%
ethena
Ethena (ENA) $ 1.24 1.62%
whitebit
WhiteBIT Coin (WBT) $ 25.01 0.62%