{"id":59078,"date":"2023-09-12T06:20:26","date_gmt":"2023-09-12T10:20:26","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=59078"},"modified":"2023-09-12T06:21:31","modified_gmt":"2023-09-12T10:21:31","slug":"vitalik-buterin-x-account-hack-caused-by-sim-swap-attack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/vitalik-buterin-x-account-hack-caused-by-sim-swap-attack\/","title":{"rendered":"Vitalik Buterin: X account hack caused by SIM-swap attack"},"content":{"rendered":"\n<p>The co-founder of <a href=\"https:\/\/coinscreed.com\/staging\/vyper-compiler-releases-v0-3-10-for-safer-ethereum-contracts.html\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum<\/a> has regained control of his T-Mobile account, verifying that a SIM-swap attack compromised his X account.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-1024x576.webp\" alt=\"Vitalik Buterin: X account hack caused by SIM-swap attack\" class=\"wp-image-59082\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-1024x576.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-300x169.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-768x432.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-18x10.webp 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-750x422.webp 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1-1140x641.webp 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Vitalik Buterin, the co-founder of Ethereum, has officially verified that the recent breach of his X (Twitter) account resulted from a SIM-swap attack.<\/p>\n\n\n\n<p>Buterin made this statement on the decentralized <a href=\"https:\/\/warpcast.com\/vitalik.eth\/0x8ea2d0\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">social media platform Farcaster<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> on September 12th, revealing that he has successfully regained control of his T-Mobile account following the hacker's exploitation of a SIM swap attack.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cYes, it was a SIM swap, meaning that someone socially-engineered T-mobile itself to take over my phone number.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>During his discussion, the Ethereum co-founder shared valuable insights and lessons from his encounter with the security breach.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" width=\"761\" height=\"176\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/9e52f433-f051-4cfc-822f-3a673681d71e.webp\" alt=\"Vitalik Buterin: X account hack caused by SIM-swap attack\" class=\"wp-image-59086\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/9e52f433-f051-4cfc-822f-3a673681d71e.webp 761w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/9e52f433-f051-4cfc-822f-3a673681d71e-300x69.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/9e52f433-f051-4cfc-822f-3a673681d71e-18x4.webp 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/9e52f433-f051-4cfc-822f-3a673681d71e-750x173.webp 750w\" sizes=\"(max-width: 761px) 100vw, 761px\" \/><figcaption class=\"wp-element-caption\"><em> Source: Warpcast<\/em><\/figcaption><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cI had seen the \u2018phone numbers are insecure, don't authenticate with them\u2019 advice before, but did not realize this.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>On September 9th, scammers took over Buterin's Twitter account, where they posted a fraudulent <a href=\"https:\/\/coinscreed.com\/staging\/nfts-and-digital-art-understanding-the-boom.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFT<\/a> giveaway, enticing users to click on a malicious link. This scheme resulted in victims collectively losing over $691,000.<\/p>\n\n\n\n<p>On September 10th, Ethereum developer Tim Beiko strongly recommended the removal of phone numbers from Twitter accounts and emphasized the importance of enabling two-factor authentication (2FA).<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Twitter opsec PSA: <br><br>If you have a phone number linked on your account, even with other 2FA, it can be used to reset your PW. Need to specifically disable it + remove phone #. <br><br>If your Twitter account pre-dates crypto, strongly recommend double-checking, and adding strong 2FA! <a href=\"https:\/\/t.co\/uXrvHYhQvJ\" target=\"_blank\">pic.twitter.com\/uXrvHYhQvJ<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; timbeiko.eth (@TimBeiko) <a href=\"https:\/\/twitter.com\/TimBeiko\/status\/1700659107764785336?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 9, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Beiko urged platform owner Elon Musk to consider making 2FA a default setting, particularly for accounts with over 10,000 followers.<\/p>\n\n\n\n<p>A SIM-swap or simjacking attack is used by hackers to gain control of a target's mobile phone number.<\/p>\n\n\n\n<p>By hijacking the phone number, scammers can exploit two-factor authentication (2FA) to access social media, banking, and cryptocurrency accounts.<\/p>\n\n\n\n<p>This incident is not the first instance involving T-Mobile and such attack vectors.<\/p>\n\n\n\n<p>In 2020, the telecommunications giant faced legal action for allegedly facilitating the theft of $8.7 million worth of cryptocurrency through a series of SIM-swap attacks.<\/p>\n\n\n\n<p>T-Mobile was embroiled in another lawsuit in February 2021 when a customer lost $450,000 in <a href=\"https:\/\/coinscreed.com\/staging\/bitcoin-whales-btc-price-dips-below-26000.html\">Bitcoin<\/a> due to another SIM-swap attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The co-founder of Ethereum has regained control of his T-Mobile account, verifying that a SIM-swap attack compromised his X account. Vitalik Buterin, the co-founder of Ethereum, has officially verified that the recent breach of his X (Twitter) account resulted from a SIM-swap attack. Buterin made this statement on the decentralized social media platform Farcaster on [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":59082,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[710,12002,12490,16400,482,4457],"class_list":["post-59078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-business","tag-hacks","tag-scams-2","tag-sim-card","tag-twitter","tag-vitalik-buterin"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/20200511_Vitalik-Buterin-ETH-Ethereum-1200x675-1.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=59078"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/59082"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=59078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=59078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=59078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}