Sophisticated Phishing Scam Bypasses 2FA on Crypto X Accounts

Phishing Campaign Bypasses 2FA to Hijack X Accounts of Crypto Influencers via Malicious App Permissions

  • New phishing campaign targets X accounts of crypto figures using advanced methods.
  • Attack bypasses two-factor authentication by exploiting X’s application support system.
  • Phishing links masquerade as Google Calendar, leveraging X’s metadata for credibility.
  • Attackers request broad permissions, allowing full account takeover if granted.
  • Security experts urge users to check connected apps and revoke suspicious access immediately.

A phishing campaign is targeting the X accounts of well-known crypto personalities, using tactics that bypass traditional security measures. Attackers are sending direct messages that appear credible and can result in a full account takeover if the recipient interacts with a malicious link. This activity is ongoing, with zero detection reported so far according to Zak Cole, a crypto developer.

- Advertisement -

The campaign does not use fake login pages or attempt to steal passwords directly. Instead, it exploits X’s own app authorization features to gain entry, sidestepping two-factor authentication (2FA). MetaMask security researcher Ohm Shah confirmed the attack is active across the platform. Reports also indicate an OnlyFans model fell victim to a less advanced version of the same scheme.

The phishing attempt begins with a message that appears to be from a legitimate source, such as an employee from Andreessen Horowitz. It contains a link showing the official Google Calendar address in X’s message preview. In reality, the URL leads to “x(.)ca-lendar(.)com,” a domain registered only days before the attacks. The preview displays “calendar.google.com” thanks to manipulated metadata, which is meant to trick users.

Once clicked, the link redirects to an X authorization page, asking the user to allow an app named “Calendar” to access their account. Technical analysis revealed that the app name includes Cyrillic characters resembling standard letters, making the fake app appear genuine. Granting access gives the attackers broad permissions, including changing profile information, posting, deleting content, and engaging with other users.

A hint that something is wrong may appear as a brief, unusual URL before redirection. On the authorization page, the app requests unnecessary access for a supposed calendar tool. After giving permission, users are redirected to a different service, Calendly, which is inconsistent with the initial Google Calendar claim. Zak Cole noted this inconsistency could alert observant users.

- Advertisement -

For those concerned their X account may be compromised, Cole recommends visiting the X connected apps page and revoking any suspicious “Calendar” access. Detailed technical findings are available in Cole’s GitHub report here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Younghoon Kim Says XRP Could Beat Gold and Silver in 2026…

Younghoon Kim predicts XRP could outperform Gold and silver in 2026.XRP trades near $1.87...

Retail Extremely Bullish on American Bitcoin; Chatter Normal

Trump Media & Technology Group Corp. (DJT) closed at $13.77 on Friday and traded...

India Drives BRICS 2026: De-Dollarization, AI & Finance 2026

India begins its BRICS presidency with a 2026 theme centered on financial cooperation, technology...

US govt-tagged wallets monitored; $50 dust traces link today

A small Bitcoin transfer of 0.000571 BTC (about $52) was sent to a wallet...

Coinbase pauses peso fiat rails in Argentina keeps crypto…

Coinbase is pausing peso-based fiat services in Argentina and will stop ARS-to-USDC and local...
- Advertisement -

Must Read

Best Metaverse Tokens to Buy on Binance for 10X Gains

Ever since Facebook renamed their company to Meta, as well as their plans to build a metaverse where we can travel into using Virtual...
Bitcoin (BTC) $ 91,102.00 1.32%
Ethereum (ETH) $ 3,134.94 1.09%
XRP (XRP) $ 2.12 5.77%
Bittensor (TAO) $ 261.93 6.89%
Polkadot (DOT) $ 2.16 1.64%
Cardano (ADA) $ 0.4014 3.89%
Chainlink (LINK) $ 13.47 2.55%
Hyperliquid (HYPE) $ 25.14 2.54%
Monero (XMR) $ 435.16 1.29%
Hedera (HBAR) $ 0.125574 5.77%
Toncoin (TON) $ 1.85 3.07%