BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Sophisticated Phishing Scam Bypasses 2FA on Crypto X Accounts

Phishing Campaign Bypasses 2FA to Hijack X Accounts of Crypto Influencers via Malicious App Permissions

  • New phishing campaign targets X accounts of crypto figures using advanced methods.
  • Attack bypasses two-factor authentication by exploiting X’s application support system.
  • Phishing links masquerade as Google Calendar, leveraging X’s metadata for credibility.
  • Attackers request broad permissions, allowing full account takeover if granted.
  • Security experts urge users to check connected apps and revoke suspicious access immediately.

A phishing campaign is targeting the X accounts of well-known crypto personalities, using tactics that bypass traditional security measures. Attackers are sending direct messages that appear credible and can result in a full account takeover if the recipient interacts with a malicious link. This activity is ongoing, with zero detection reported so far according to Zak Cole, a crypto developer.

- Advertisement -

The campaign does not use fake login pages or attempt to steal passwords directly. Instead, it exploits X’s own app authorization features to gain entry, sidestepping two-factor authentication (2FA). MetaMask security researcher Ohm Shah confirmed the attack is active across the platform. Reports also indicate an OnlyFans model fell victim to a less advanced version of the same scheme.

The phishing attempt begins with a message that appears to be from a legitimate source, such as an employee from Andreessen Horowitz. It contains a link showing the official Google Calendar address in X’s message preview. In reality, the URL leads to “x(.)ca-lendar(.)com,” a domain registered only days before the attacks. The preview displays “calendar.google.com” thanks to manipulated metadata, which is meant to trick users.

Once clicked, the link redirects to an X authorization page, asking the user to allow an app named “Calendar” to access their account. Technical analysis revealed that the app name includes Cyrillic characters resembling standard letters, making the fake app appear genuine. Granting access gives the attackers broad permissions, including changing profile information, posting, deleting content, and engaging with other users.

A hint that something is wrong may appear as a brief, unusual URL before redirection. On the authorization page, the app requests unnecessary access for a supposed calendar tool. After giving permission, users are redirected to a different service, Calendly, which is inconsistent with the initial Google Calendar claim. Zak Cole noted this inconsistency could alert observant users.

- Advertisement -

For those concerned their X account may be compromised, Cole recommends visiting the X connected apps page and revoking any suspicious “Calendar” access. Detailed technical findings are available in Cole’s GitHub report here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

DBS Retail Gold Tokens Launch in 2026

DBS will launch a tokenized physical Gold product for retail customers via its digibank...

npm 12 Disables Risky Scripts by Default

GitHub is introducing major security changes to npm version 12, disabling install scripts by...

Bitcoin Holds at $62K Amid Market Crash; Stocks Lose $1.1T

Bitcoin holds steady near $62,000 amid a major U.S. stock market crash that erased...

ARK Sells $7.5M in Robinhood Shares Despite Rally

Cathie Wood's Ark Invest sold 89,915 shares of Robinhood Markets worth approximately $7.5 million,...

Teen steals $13M in crypto via Google scams

A Canadian teen, Trenton Richard Johnston, pleaded guilty to conspiracy to commit money laundering...

Must Read

10 Best Crypto to Mine Without Special Hardware Equipment

A lot of people mostly think that it takes a difficult process to mine cryptocurrency. today we are going to show you some of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading