Vitalik Buterin sim-swap hack exposes Twitter Blue account security flaw

cyptouser8 months agoCryptocurrencies News224

Vitalik Buterin sim-swap hack exposes Twitter Blue account security flaw

Ethereum co-founder Vitalik Buterin confirmed that his X (formerly Twitter) account was breached via a sim-swap attack, according to a Sept. 11 post on Warpcast.

A sim-swap attack is a scheme that exploits a vulnerability in specific two-factor authentication methods, where a phone call or text message serves as the second authentication step. This method enables attackers to access their victims’ text messages, emails, contact lists, bank accounts, social media profiles, and other sensitive and private data.

Buterin explained that he did not know that phone numbers were sufficient to password reset a Twitter account even if not used as two-factor authentication. He added:

“A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the “phone numbers are insecure, don’t authenticate with them” advice before, but did not realize this.”

According to him, he might have added his mobile number to the social media platform when he was registering for Twitter Blue. Twitter Blue is a subscription service that grants users access to premium app features and exclusive benefits like expanded reach, prioritized tweets, and other features on the X application.

Meanwhile, Buterin expressed joy in being on Farcaster, a decentralized social media protocol that allows users to recover their accounts via an Ethereum address. Warpcast is built on this protocol.

Buterin did not provide additional information on whether he would ever return to X.

On Sept. 9, Buterin’s X account was used to promote a phishing link that stole digital assets, including non-fungible tokens (NFTs) from wallets that interacted with it. The incident led to the loss of around $700,000.

Following the hack, Binance CEO Changpeng Zhao urged the crypto community to take caution when reading social media posts and advised the platform to introduce more security features. He added:

“Twitter’s account security is not designed as financial platforms. It needs quite a bit more features: 2FA, login id should be different from handle or email, etc.”


The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Owocki rejoins Gitcoin amid shifting landscape and open-source funding needs

In a recent Gitcoin forum post, Kevin Owocki, co-founder of Gitcoin, outlined his intentions fo...

BitBoy removes host Ben Armstrong amid meme coin controversy – reports

Ben Armstrong, the influential figure behind BitBoy Crypto, has reportedly left the company, leaving...

Solana co-founder backs Ethereum amid MakerDAO fork consideration

Solana co-founder backs Ethereum amid MakerDAO fork consideration

Solana’s (SOL) co-founder, Anatoly Yakovenko, has cautioned the blockchain community against harbori...

Hong Kong social media star arrested for promoting controversial JPEX crypto platform

Hong Kong police officers have arrested crypto influencer Joseph Lam Chok for promoting the JPEX cry...

Bitcoin, Solana community calls out Coinbase CEO on crypto payment vision

Bitcoin, Solana community calls out Coinbase CEO on crypto payment vision

The vision for a future where crypto payments are instant, accessible, and global has ignited a spir...