Bitcoin Forum
July 07, 2024, 06:47:53 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Kucoin Twitter account hacked, $22k lost  (Read 239 times)
Accardo
Hero Member
*****
Offline Offline

Activity: 1134
Merit: 518


Leading Crypto Sports Betting & Casino Platform


View Profile
April 28, 2023, 05:45:59 PM
 #21

Isn't it supposed to be an inside job, since they claim without any proofs that they had twitter 2fa enabled?
If it was an inside job, then it was a pretty bad one. 22k is nothing compoared to some bigger hacks and somehow I doubt that someone from Kucoin would risk so much for so little. By the way, how exactly could they prove that they had 2FA enabled? You either belive what they claim, or not.


Inside job in such scam as this one, isn't one sided, it could also be from the twitter side. I could remember when the likes of Barack Obama's twitter account was hijacked and used for a similar scam, the hackers, teenage boys, when apprehended said that they tricked, through spearphishing, an insider on twitter who helped them execute the task and bypassed them to tweet with accounts owned by top celebrities. A scam, however severely, is simply bad. Hence, the stolen amount shouldn't be considered as the only reason why their twitter account was hijacked. They could be some information that the hacker needed to get on the Kucoin twitter page, exaggerating, then dropped the tweet. And I don't think they were right about how long the account was on the hacker's custody, as they judged from the moment the tweet was made to the time they were aware of what's happening.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Husires
Legendary
*
Offline Offline

Activity: 1596
Merit: 1288


View Profile WWW
April 29, 2023, 02:05:23 AM
 #22

Do any of you have any snapshots of the nature of the scam that happened? Are they links to access your account, double money scam, free gift trick or what? In just 45 minutes, and through tweets, a scammer can collect more than 20k USD, which is not a small amount, and it is additional evidence that many cryptocurrency users need more awareness and investment in learning than losing their money in such ways.

I wish their cold/hot storage is managed by a more professional team.
Rikafip (OP)
Legendary
*
Offline Offline

Activity: 1806
Merit: 6183


Iznad svih Hrvatska!


View Profile WWW
April 29, 2023, 06:45:31 AM
 #23

Do any of you have any snapshots of the nature of the scam that happened? Are they links to access your account, double money scam, free gift trick or what?
It was a pretty basic scam attempt in which attacker shared fake Kucoin website and promised free money. People fall for these type of scams even without announcement coming from the exchange's official Twitter account so I am actually surprised that more people didn't lose money.


https://twitter.com/NFTherder/status/1650272867785777153


██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
eaLiTy
Hero Member
*****
Offline Offline

Activity: 2814
Merit: 911

Have Fun )@@( Stay Safe


View Profile
April 29, 2023, 07:40:03 PM
Last edit: April 30, 2023, 09:58:21 AM by eaLiTy
 #24

What a shame, but still kudos reimbursing the users affected. I don't know how their handle was hacked, isn't 2fa is forcedrequired to every verified handle in twitter? How is it possible though to breach 2fa?
It is surprising that Kucoin is reimbursing users that lost money because of the hack in Twitter as majority might have sent money thinking that they are doubling the amount, the usual scam that takes place in this space Posted a phishing link in their Twitter handle and thereby lost money and hence they are doing the right thing by reimbursing the users.

The verification process in Twitter changed after Elon Musk took over as anyone paying $8 can get verified, so i doubt there will be mandatory 2 FA.

It is surprising that Kucoin is reimbursing users that lost money because of the hack in Twitter
I don't think that its surprising at all since their account got hacked due their own mistake and no one else's. Imho, its the least that they could so.
I retracted my statement because it was a phishing link, when i initially posted them i thought it was a doubling scam and they are doing the right thing.

Fact remains that, it is not safe to click on any random link when you log into exchange even through their official social media handle. Users need to be responsible when financial assets are at stake to avoid these mishaps.
ololajulo
Sr. Member
****
Offline Offline

Activity: 2240
Merit: 270


SOL.BIOKRIPT.COM


View Profile
April 29, 2023, 08:10:19 PM
 #25

What a shame, but still kudos reimbursing the users affected. I don't know how their handle was hacked, isn't 2fa is forcedrequired to every verified handle in twitter? How is it possible though to breach 2fa?

Contrary to popular belief 2FA is not impenetrable, especially if they used mobile phone number.
I guess sms 2fa is not available on twitter, i remember elon doesn't like 2fa and keep tweeting it previously.
My apologies but how did the kucoin twitter account hack allow access to the exchange fund? Does this make a difference to everyone who has a Twitter account and cryptocurrency?

B.I.O.K.R.I.P.T|
  BiokriptX Fair Launch is now live in PINKSALE
|🟣 Twitter
🔵 Facebook
🟣 Telegram
Rikafip (OP)
Legendary
*
Offline Offline

Activity: 1806
Merit: 6183


Iznad svih Hrvatska!


View Profile WWW
April 29, 2023, 08:15:13 PM
 #26

It is surprising that Kucoin is reimbursing users that lost money because of the hack in Twitter
I don't think that its surprising at all since their account got hacked due their own mistake and no one else's. Imho, its the least that they could so.


My apologies but how did the kucoin twitter account hack allow access to the exchange fund? Does this make a difference to everyone who has a Twitter account and cryptocurrency?
Its not the exchange that got hacked, but Kucoin Twitter account that attacker then used to share phishing link.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
PX-Z
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 873


Top Crypto Casino


View Profile WWW
April 29, 2023, 10:19:24 PM
Last edit: April 29, 2023, 10:31:19 PM by PX-Z
Merited by ololajulo (1)
 #27

My apologies but how did the kucoin twitter account hack allow access to the exchange fund? Does this make a difference to everyone who has a Twitter account and cryptocurrency?
Its not the exchange that got hacked, but Kucoin Twitter account that attacker then used to share phishing link.
To be precise, kucoin twitter was hacked and tweet a fake giveaway scam that leads by accessing the phishing site and got scammed. So no exchange was hacked particularly.

It doesn't mention how the scam happened particularly if its the users send the funds particularly from their kucoin accounts or the scammers/hackers login to their users' account and withdraws their assets. If its the latter, kucoin should implement another security that it disabled from withdrawing in 24 hours after logging in a new device, or needs a sms, email and 2fa verification for withdrawals using a new logged in device.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!