A pseudonymous on-chain investigator says he uncovers a malicious scheme that uses hacked accounts on social media platform X to promote a fake memecoin.
ZachXBT says the cybercriminal stole the login credentials of high-profile X accounts by sending phishing emails impersonating the X Team.
The emails appear to indicate X’s policy violations in order to create a sense of urgency and persuade recipients to click on a malicious link.
“A threat actor stole approximately $500,000 last month by compromising more than 15 X accounts (Kick, Cursor, Alex Blania, The Arena, Brett, etc.).
Each of the 15 ATOs was directly linked by identifying the operator’s address for each scam.
The attacker created a bridge between Solana and Ethereum to obscure the funding source.”
According to the smart contract platform Neutron, the perpetrator sent fake copyright infringement emails in which he targeted those affected
Once the X account is compromised, the attacker logs out all sessions, changes security settings, and then…