Fraudsters are exploiting fake 'new device login' alerts to hijack X accounts and fuel crypto‑scam operations
Executive summary: Fraudsters are sending fake ‘login from a new device’ messages to X (formerly Twitter) users in order to steal passwords for use in crypto scams and further phishing attacks. The scheme illustrates a rising trend of credential phishing targeting social media platforms to enable cryptocurrency fraud, posing financial risks to users and reputational risks to the platform.
Who is involved: X users, fraudsters impersonating X’s security team, and crypto‑scam operators who exploit the stolen credentials.
Likely next: X may roll out additional login‑verification prompts and users are advised to enable two‑factor authentication; regulators could issue guidance on social‑media phishing linked to crypto fraud.
The Guardian reports that attackers are sending deceptive emails mimicking X’s security notifications, prompting users to reveal passwords that are then used to steal cryptocurrency or launch further phishing waves. The campaign highlights how credential‑theft tactics are increasingly tied to the crypto ecosystem, where stolen credentials can be monetised quickly. While the article does not quantify the scale, it underscores a growing threat vector for both platform users and the broader digital‑asset market.
Timeline
- — ‘We noticed a login from a new device’: the message from fraudsters targeting your X account (The Guardian — Business)
Analysis — what this means
Sectors affected
- Social media (X/Twitter)
- Cybersecurity authentication services
- Cryptocurrency exchanges and wallet providers
Historical parallels
- 2020 Twitter Bitcoin scam (July 2020) where compromised high‑profile accounts promoted a crypto giveaway
- 2022 LinkedIn credential phishing campaign that harvested passwords for subsequent crypto‑theft attempts
Sources
- ‘We noticed a login from a new device’: the message from fraudsters targeting your X account — The Guardian — Business