Prominent U.S. Twitter Accounts Hacked

13
8.2

Published -

Searching the network...

Twitter’s blue-check system became a $110,000 crime scene in a single afternoon.

On July 15, 2020, dozens of the most-followed accounts on Twitter — Barack Obama, Joe Biden, Elon Musk, Bill Gates, Jeff Bezos, Kanye West, Kim Kardashian, Apple, Uber, and crypto exchanges Coinbase and Gemini among them — simultaneously posted the same bitcoin scam. Each tweet promised to double any bitcoin sent to a specific wallet within 30 minutes, framed as a charitable gesture “giving back to the community.” Twitter’s emergency response included freezing the ability of every verified account to tweet or reset a password for hours while engineers scrambled to contain the damage.

  • Attackers hijacked verified accounts of Obama, Biden, Musk, Gates, Bezos, Kanye West, Kim Kardashian, Apple, Uber, Coinbase and Gemini to push a bitcoin-doubling scam.
  • By the morning of July 16, the primary wallet cited in the fraudulent tweets had logged more than 320 transactions worth over $110,000 before the messages were removed.
  • Twitter disabled tweeting and password resets for all verified accounts for several hours, then confirmed the breach stemmed from a social engineering attack on employees with access to internal admin tools.

Scam Operation Visible In Plain Sight

The messages followed an identical script across every hijacked account: send bitcoin to a listed address, get double back within half an hour. Because the posts came from accounts with tens of millions of followers and Twitter’s own blue-check verification badge, the scam had an air of legitimacy most phishing attempts never achieve. Coinbase and Gemini — companies whose entire business is built on crypto trust — were among the accounts weaponized to push the fraud, which only sharpened the irony for anyone watching the transactions pile up in real time on the public blockchain ledger.

Twitter’s Emergency Lockdown

Rather than chase down each compromised account individually, Twitter took the blunt-force option: it temporarily blocked every verified account from tweeting or resetting a password. The freeze lasted several hours while the company worked to determine how deep the intrusion went and whether attackers still had active access to internal tools. It was an extraordinary step for a platform that many governments and news organizations rely on for real-time information, and it left millions of verified users locked out with no timeline for restoration.

Inside the Breach

Later that evening, Twitter Support released preliminary findings confirming the attack wasn’t a series of individually cracked passwords — it was a coordinated social engineering operation aimed at company employees who had access to internal administration systems. Once inside, the attackers were able to override account credentials directly and tweet as the accounts themselves, bypassing two-factor authentication and any password-based defenses entirely.

Dmitri Alperovitch, co-founder of CrowdStrike, called it “the worst hack of a major social media platform yet.”

That assessment set off immediate alarm among cybersecurity researchers and lawmakers, not just over the money stolen but over what the same access could have done with an election four months away. A similar internal-tools compromise has already reshaped how companies think about ransom and extortion risk — see the aftermath of the Colonial Pipeline crypto ransom recovery for how seriously federal investigators now treat attacks that ride in through employee credentials rather than brute-force hacking.

The Companies Caught in the Crossfire

Apple and Uber’s corporate accounts were swept up alongside the celebrity and political profiles, a detail that mattered for reasons beyond the bitcoin scam itself. Apple in particular has spent years fighting to protect its brand and its bottom line in other regulatory arenas, including its ongoing dispute detailed in the EU court’s ruling on Apple’s $15 billion tax bill — a reminder that even the biggest tech names remain exposed on fronts they don’t fully control, whether it’s tax courts or a stranger inside Twitter’s own admin panel.

Twitter had purged the fraudulent tweets and the specific wallet address by the morning of July 16, but the $110,000-plus already collected wasn’t coming back through any takedown. The company said its investigation into exactly how many employee accounts were compromised and how far the attackers’ access extended was still ongoing as of that morning — the real number of victims inside Twitter’s own systems hadn’t been made public yet.

8.2 Total Score

User Rating: 3.42 (33 votes)
Advanced Search Options
Searching the network...
InfoSearched | News Research & Information
Logo