API Download the RootData App

The cryptocurrency community is facing a new type of X account hijacking attack that can bypass two-factor authentication

Sep 26, 2025 11:24:45

Share to

ChainCatcher message, cryptocurrency developer Zak Cole disclosed that a new type of phishing attack is targeting the X (formerly Twitter) accounts of members of the crypto community. This attack disguises itself as an authorization request from the Google Calendar app, tricking users into granting full account control permissions. Attackers exploit the application authorization mechanism of the X platform, completely bypassing passwords and two-factor authentication.

MetaMask security researchers have confirmed that this attack is active in the wild. Users are advised to visit the connected apps page on X to check and revoke any suspicious "Calendar" app authorizations to ensure account security.

Recent Fundraising

More
-- Dec 26
$1M Dec 25
$35M Dec 24

New Tokens

More
Dec 23
Dec 20

Latest Updates on 𝕏

More