21 ms·
Live BTC transactions in Twitter hack
- dang 6y agoThe general thread about the hack is https://news.ycombinator.com/item?id=23851275 https://news.ycombinator.com/item?id=23851275. Please discuss the general aspects there and the BTC aspects here.
- throwaway888abc 6y agoFascinating to see the transactions going up (refresh the page) every minute as the scam propagate
- baal80spam 6y agoSomeone just sent 4.5 BTC...
- deleted 6y ago[deleted]
- jolmg 6y agoAt 13:47 PDT, there's a 60.4 BTC one[1]. That alone is half a million USD. EDIT: Replies are right. Now I see that the majority of it went to the same address as the source. [1] https://www.blockchain.com/btc/tx/4df1391d936d3256ce84a867e15b9ef529161bf6b8ef48a1a1a7ec062d9f3a12 https://www.blockchain.com/btc/tx/4df1391d936d3256ce84a867e1...
- deleted 6y ago[deleted]
- baal80spam 6y agoWait, where do you see that? On the linked page, I can see the following: Total Received: 11.39184745 BTC edit: OK, either this is strange or I don't understand how it works.
- jolmg 6y agoYeah, I also don't understand how one can have multiple destination addresses in a single transaction.
- oarsinsync 6y agoAs a a sender, you have a coin of amount X, and you split it up and send it wherever you like If your coin is 1 and you want to send one person 0.2 and another person 0.3, you can do that as a single transaction to three destinations, one with 0.2, another with 0.3 (to the people you’re sending to) and a final one with 0.5 back to one of your own addresses (aka a change wallet)
- oarsinsync 6y agoYou’re fine. The GP doesn’t understand. Only 0.00291948 BTC was sent to the hacker wallet. The remainder went to other wallets. The vast majority went back to the person making the transaction (IE nowhere)
- bobbyi_settv 6y agoWhat is the point of someone sending btc back to himself?
- lawn 6y agoThat's just how Bitcoin works. Say you have 1 BTC on an address and you want to send 0.1 to someone, you still need to send all of the money. So wallets "split" the 1 BTC into 0.1 and 0.9 outputs, sending the 0.9 to yourself to another address you control. It's called a change address. Modern wallets do this automatically, but it can be confusing to look at it on a blockchain explorer.
- shuntress 6y agoMaybe she is just trying to flex.
- oarsinsync 6y ago
- dnprock 6y agoIn this transaction, there's only 0.00291948 BTC sent to the scamming address: bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh. It's time to learn more about Bitcoin. :)
- deleted 6y ago[deleted]
- 1f60c 6y agoI wasn’t sure what I was looking at, until I googled the Bitcoin address (bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh): Several high-profile Twitter users, including Elon Musk, Bill Gates, and the official Uber account appear to have been hacked, and all promoted that address, saying any funds sent to it will be doubled.
- gruez 6y ago>Several high-profile Twitter users, including Elon Musk, Bill Gates, and the official Uber account appear to have been hacked, and all promoted that address, saying any funds sent to it will be doubled. speculation time: How did those accounts get hacked? Did they all get spearphished? Did twitter get compromised?
- o-__-o 6y agoOr was it a marketing platform that was owned? I worked for one a few years back and they used the same fb key for all of their 500 musicians they represented. One day facebook enforced key rotation and a bunch of fan sites went dark. Imagine if someone got access to our codebase, this same type of nefarious action would have happened The curtain has been pulled back for some. Their favorite tweeters aren’t actually tweeting themselves Edit: I also wonder if it’s an elaborate money laundering scheme. Mix coins with deniability. Combine with the Epstein drama, maybe there’s more to what meets the eye. Either way it’s popcorn time
- Nightshaxx 6y agoI do not think this is true. Please tell me what marketing company would both manage Obama's very professional twitter, and at the same time commit fraudulent manipulation of Tesla's stock price. If what you are saying was true, there would be some sort of evidence. Plus musicians/pop stars are very different from Official corporate twitter.
- milofeynman 6y agoIt's got to be a 3rd party authed w/ the Twitter account, I'd guess.
- seibelj 6y agoAt Poloniex, we quickly blacklisted this address. Prevents all of our users from sending money to them. Many exchanges likely can do the same thing.
- mrtksn 6y agoWhile this is a good measure, what does it mean to the decentralization promise of Bitcoin?
- drexlspivey 6y agoIt means dont keep your money at exchanges if you want to control them
- celticninja 6y agoAlso protects the stupid. You can still send this address BTC. You just need to withdraw it to your own wallet first. Which buys the user time in which to discover it's a scam
- seibelj 6y agoPeople who use exchanges are traders (retail or professional) and hodlers who don't want to deal with the intricacies of managing 100+ coins on 50+ blockchain networks. The decentralization of cryptocurrencies is not an all-or-nothing proposition - users can choose the level of decentralization they would like based on their preferences. What I like most about decentralization is that anyone in the world can create a new crypto business on the blockchain rails, integrate with everyone else, and attract users. Of course there are real-world repercussions if your physical entity is in a locale with laws that you violate, but it is orders of magnitude easier to start a crypto exchange than a traditional bank.
- cortesoft 6y agoWon't this end up like email, though? Sure, anyone can set up their own business... however, 90% of people will be on a few large providers, and those providers will end up blocking transactions coming from unknown new providers (to prevent scams). Decentralization doesn't stop consolidation.
- Tenoke 6y agoI'm guessing they'll end up with ~100-300k total after all is done and they tumble, launder etc. the coins. I am not sure how much that is for them but there are claims that the 'regular' version of that scam already nets millions a year.
- aeternum 6y agoBetter payout than the $2.9k for disclosing this to Twitter via bug bounty.
- thephyber 6y agoDo you have any evidence this is a Twitter flaw and not a 3rd party app?
- lytedev 6y agoOP's point holds. A third party likely has a less-rewarding bug bounty, doesn't it?
- manquer 6y agoIf the twitter security model allows third party apps access to verified high profile accounts without auditing the security of that app it is still a flaw in Twitter's processes. Twitter after all has a lot higher risk than the 3rd party app, it is in their interest to make sure partners dealing with high profile accounts or partners handling a large volume of accounts are also secure.
- dredmorbius 6y agoNumerous dupe submissions, primary discussion: https://news.ycombinator.com/item?id=23851275 https://news.ycombinator.com/item?id=23851275
- ve55 6y agoThey do use a lot more addresses than just this one too
- cbsks 6y agoIt would be interesting if the scammers started sending back twice as many bitcoins, as promised, from the same address. It could be a real-time ponzi scheme!
- dredds 6y agoIn that scenario 10% per month would be a sufficient inducement and likely more believable given the volatility.
- im3w1l 6y agoIirc, ponzi schemes used to be welcomed on the bitcointalk forums. And people would sign up, knowing they were ponzis. Kinda like people playing roulette at a casino knowing they are playing a losing game but do it anyway for the thrill.
- Thorentis 6y agoThey're not always losing schemes (i.e. only some people lose), it just depends on if you're at the end or not. The reason they were encouraged is because people enjoyed gambling on how long they would last, and it was extra incentive to use BTC, etc.
- Cthulhu_ 6y agoThat's how it's done in Eve Online, the money duplication scam is common there. How it works is that the scammer announces in an area (usually the trade hub system Jita) that they're quitting and giving away all their money. They link to a webpage that (they claim)_shows all of their bank transactions, using Eve's API. You send them 100K just to try it out, they send you back 200K, both transactions show up in the webpage. "Ha it works!", you say, sending them 1M, they send you 2M back. Until at any point, they stop sending you money back. Their outgoing transaction shows up in the webpage, but ingame you never received anything. When you message them they go "must be a bug, I sent the money because look at my transaction log. Contact support, not my problem, the money left my account" You'd think it just doesn't work, why would anyone fall for that, but plenty fall from it. Plenty of people try and outsmart them as well, making use of it to earn some money. But as another commenter pointed out, it can be like a game of roulette.
- rvz 6y agoYou can see the high profile Twitter accounts hacked here by searching the address in Twitter with the verified filter: bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh filter:verified
- Scoundreller 6y agoHere's a link to make your life easier: https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh%20filter%3Averified&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8... They'll all say "Twitter Web App" as the tweet source. If you search through all accounts (ie: also the unverified ones), you see plenty that say Twitter for iPhone or Twitter for Android. Those are likely trolls. Those are here: https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh&src=typed_query&f=live https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
- rvz 6y agoThanks, but they have now moved to another address and the hackers are at it again: Replace the old BTC address with this one: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l
- mikeyouse 6y agoSeems like it would have been more profitable to take a huge short position in TSLA and hack Elon's Twitter to post something about a SEC investigation for accounting fraud and that you'd need to restate multiple years' worth of earnings.
- ealexhudson 6y agoMore profitable but more likely to be caught.
- mikeyouse 6y agoProbably true - though there's already a ton of short interest in the company. Seems like you could take a few million in profits and still blend in fairly seamlessly.
- paulpauper 6y agoyeah and then the SEC freeze your account and you go to jail and get $0
- Havoc 6y agoSEC can just reverse the trade. For shady sht crypto is superior
- puranjay 6y agoThe stock market is way more regulated and you'd be caught
- spyder 6y agoOr they could have been doing something similar with cryptos without risking SEC or requiring ID on exchanges: using the twitter accounts to announce partnerships with one of the cryptocurrencies. Probably less gain then with stocks but more than with this simple scam.
- pdr2020 6y agoQuite genius.
- paulpauper 6y agolooks sms porting..been 3 years now and still no one has a good fix for this
- rodiger 6y ago...no, you aren't going to get access to all these high profile accounts at the same time with sms porting. This is almost definitely internal.
- paulpauper 6y agoi didn't realize the extent until now. Way more than just 4 ..more like 40+
- sleepybrett 6y agoSeems like they could have sold this hack for way more than this will make them.
- logicslave 6y agoIts almost suspicious how poorly this turned out for them. I suspect theres more going on than this
- rcpt 6y agoIt's such a dumb way to make money with this kind of power that I'm more likely to believe that Elon really is sending back 2x BTC
- manquer 6y agoIt is perhaps a proof of ability, burning a zero day might be worth it, if you have others you can sell, also if the zero day was one time use or likely getting closed soon , the value might be not as high as it may look.
- donkeyd 6y agoI've been thinking about this for a bit. Perhaps these were crypto scammers that discovered a God mode and used it. To actually monetize this hack in another way would mean getting in touch with some truly powerful/evil people and possibly putting yourself in danger. Creating a couple of wallets and a website can be done mostly anonymously. Sure, the money is a lot less, but so is the risk.
- jdminhbg 6y agoVia Tyler Cowen [0]: > If you've ever watched Goldfinger, you have to wonder if the real ploy isn't somewhere else, such as auctioning off DMs, blackmail, etc., and the bitcoin thing just proof of concept. 0: https://twitter.com/tylercowen/status/1283518906041278468 https://twitter.com/tylercowen/status/1283518906041278468
- 6y ago
- byteshock 6y agoThey reposted it on the cash app account but with a different address. The exchanges are going to have a field day monitoring twitter. New address: bc1qwr30ddc04zqp878c0evdrqfx564mmf0dy2w39l Tweet: https://mobile.twitter.com/CashApp/status/1283522007695597570 https://mobile.twitter.com/CashApp/status/128352200769559757...
- ben174 6y agoSo strange that twitter can't automatically filter these. The message format is pretty consistent. Surely they could write something to at least put tweets matching this pattern in a moderation queue.
- ageitgey 6y agoThey are blocking tweets with that address now. I'm guessing that they still have no idea what the root cause is.
- byteshock 6y agoSomebody is getting fired today... Edit: I was only making a joke, relax. Most likely it’s not a single person’s mistake. It’s just something you say when shit hits the fan.
- floatingatoll 6y agoPromoting, praising, or otherwise endorsing the kind of reaction you state is inexcusable in IT Operations. Your unstated assumptions-by-framing are: 1) A single person is responsible for the flaw. 2) A single person is either already under performance review or committed gross neglect of duties. 3) The above single person will be terminated rather than retrained. If this is how you would speak about your own employees during a security incident, your business deserves to fail. If this is how you expect to be treated by your employer during a security incident, you should seek employment elsewhere.
- 21eleven 6y agoHopefully most of this bitcoin is just the attacker sending their own funds to make it look legitimate.
- beervirus 6y agoHow many people who would fall for this scam would also know how to look at the blockchain data?
- paulpauper 6y agoit is amazing given how long twitter has been around that such a powerful exploit still existed, assuming it was not an insider job. It also shows that bug bounties will not prevent the really bad stuff. The payoff from exploiting such a huge bug is in the millions, which no bug bounty program will ever pay,
- celticninja 6y agoThis hack isn't going to generate millions for the attackers. But you're right that it was still outweigh any bug bounty
- 1-6 6y agoCan Twitter put up a banner warning folks not to submit crypto???
- blisseyGo 6y agoIt's been at least 3 years and they still haven't made a fix for the spam comments until Elon Musk's tweets for crypto scam from user account names of "Elon_Musk" or others. This should be such an easy way to block. Don't even allow new user accounts with "Elon" and "Musk" in it unless verified. I have been seeing this for over 3 years and no fix.
- Nextgrid 6y agoCrypto scams that are trivial to block have been going on for years. There is no reason to believe Shitter cares about the well-being of their users, and frankly they were right because people kept using this rotten platform despite that. Maybe now things will change.
- puranjay 6y agoWhat kind of heat would the person or party that started this hack get? What could be the expected consequences? Going after political figures, including the former President of the US, should, I think, trigger a digital man hunt.
- ex3ndr 6y agoIt actually looks like all targets are enemies of current POTUS
- bayesbot 6y agonot Kanye
- wh-uws 6y agoElon Musk is not.
- deleted 6y ago[deleted]
- paulpauper 6y agothis is motivated by profit. nothing political. potus being hacked would escalate to national security threat and possibly force twitter to shutdown by decree. which the hacker is smart enough to know not to tread
- monokh 6y agoI really didn't imagine a purely financially motivated hack could be turned into politics. I guess I underestimate the levels of innovation.
- ex3ndr 6y agoCurrent administration is purely financially motivated though
- blisseyGo 6y ago
- odomojuli 6y agoIs it significant at all that this is happening on US Tax Day?
- dividedbyzero 6y agoWhat is US Tax Day?
- henryfjordan 6y agoThe day taxes are due in the US (or you need to file for an extension). If you don't file by today, you'll owe late fees. Usually it's in April but this year it was delayed for Covid.
- jdminhbg 6y agoThe day tax filings and payments for the year are due. Normally Apr 15, postponed to today due to Covid-19.
- EamonnMR 6y agoToday all US residents need to file their taxes. Totally missed this story because I was busy filing them. Glad they nailed twitter and not the IRS.
- dairylee 6y agoNo
- rcpt 6y ago+0.00001337 BTC which one of us did that?
- odomojuli 6y ago1JustReadALL1111111111111114ptkoK 0.00000666 BTC 1TransactionoutputsAsTexta13AtQyk 0.00000667 BTC 1YouTakeRiskWhenUseBitcoin11cGozM 0.00000668 BTC 1forYourTwitterGame111111112XNLpa 0.00000669 BTC 1BitcoinisTraceabLe1111111ZvyqNWW 0.00000670 BTC 1WhyNotMonero777777777777a14A99D8 0.00000671 BTC bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh 0.00001337 BTC Can anyone explain what happened in this block of transactions to me?
- drexlspivey 6y agoThese are bitcoin eater addresses (essentially receive only addresses), you can create addresses like these if you bruteforce the checksum bytes however you dont have the private key for them. I think the more famous one is 1BitcoinEaterAddressDontSendf59kuE
- uncoder0 6y agoSomeone is trying to communicate with the hacker using invalid addresses.
- VMG 6y agonot with the hacker but with the cryptocurrency community
- rubatuga 6y agoYou can send BTC to any address you want
- gjkhkldajghl 6y agoMaybe I'm missing something, but I'm assuming someone is critiquing the scammer as foolish for using bitcoin instead of Monero because it is more difficult to cash out, as bitcoin is less anonymous than Monero?
- legopiece 6y agoAgreed. They are basically telling the scammer(s) to use a more anonymous & untraceable crypto next time, as everyone will be following the coins in that BTC wallet now, which makes it much more difficult to "launder". I guess the choice of BTC but the scammer(s) was based on its much bigger popularity relative to Monero (many people have a few satoshis somewhere, but not many have some monero lying around)
- deleted 6y ago[deleted]
- zacharycohn 6y agoThis is the first thing I looked up when I heard about the attack. Surprisingly few transactions given the scale.
- rbanffy 6y agoPhineas Barnum was right.
- blablafd 6y agoThanks BTC which make it true! BTC is the only thing that is totally useless and harmful!
- cryptozeus 6y agoIs the address also sending out money? It appears that way.
- VWWHFSfQ 6y agoThe hackers made more profit in 5 minutes than Twitter has in 10 years
- gkoberger 6y agoThat's not true. The hackers made about $100k (assuming everything in the wallet is a real transaction from someone who was scammed), and Twitter's revenue in 2019 was $3.46 billion. Twitter's been posting a profit since 2018.
- phreeza 6y ago> Twitter's been posting a profit since 2018. 12 years after it was founded.
- strogonoff 6y agoThis may be an unpopular opinion to voice here, but if we take a time-tested construct X and remove physical proximity constraints restricting its scale, we must hold the resulting technology to much, much higher standards than the old X—because scale, along with potentially unbounded yet-unknown upsides, brings potentially unbounded yet-unknown negative implications, and we should be concerned about the latter more than the former.
- thinkloop 6y agoWhat exactly are you referring to?
- mumblemumble 6y agoI think the gist is, "Electronic payment platforms, including cryptocurrency, need more built-in consumer protection than cash money does, because they're much bigger pots of honey."
- totony 6y agoOr perhaps it's social media criticism. Journals were location-restricted vs now where twitter controls a lot of it.
- strogonoff 6y agoThank you, yes, that’s one of the corollaries. In general, we (humans) are not great at assessing the potential of negative/positive effects beyond certain scale (black swans and all), and analogies along the lines of “like X, but digital” are just too attractive. Those analogies are dangerous, since the scale makes Y an entirely new thing with effects that cannot be predicted based on its outside similarity to X. This applies to many concepts including infosec (e.g., likening remotely exploitable vulnerabilities to faulty door locks), cryptocurrency, mass media, though when I was writing the above I mainly was specifically thinking about cryptocurrency. It is misleadingly similar to “cash, but digital and not backend by government”, but its scale makes it something we actually have never had to deal with before, with unknown implications that go both ways. Considering the potential effects can be unbounded, limiting it in order to bound the downsides ones might be a rational (but both unpopular, boring and ambiguous) thing to do, even if it also limits the upsides.
- UnbugMe 6y agoYou are gay. For real.
- totorovirus 6y agoThey hacked the twitter for 12 bitcoins?
- shlant 6y agoyea there are a lot of people on twitter poking fun at the fact that there were probably MUCH more lucrative things you could have done with that kind of access. Seems like a quick smash and grab by some teenagers or something
- pdr2020 6y agoAgreed.
- electro_blah 6y agoor just diverting attention from something else (that might be more "profitable") while making some extra profit.
- RcouF1uZ4gsC 6y agoThis has to be the biggest advertising flop in history! The hackers basically ran an advertisement on the most followed Twitter users in the world, and had 374 conversions (based on the number of transactions as of the time of this post).
- deleted 6y ago[deleted]
- StefanoC 6y agoELI5: how will they get the money out of there without getting busted?
- vs4vijay 6y agoIf you take a look at some of the transactions, you will see some interesting addresses like: 1JustReadALL1111111111111114ptkoK 1TransactionoutputsAsTexta13AtQyk 1YouTakeRiskWhenUseBitcoin11cGozM 1BitcoinisTraceabLe1111111ZvyqNWW 1WhyNotMonero777777777777a14A99D8 1forYourTwitterGame111111112XNLpa Link: https://www.blockchain.com/btc/tx/67b814526ae6ee78a16059bfcfc06ed7768c92c58f3409367cb180627631ddbe https://www.blockchain.com/btc/tx/67b814526ae6ee78a16059bfcf...