[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

The cryptocurrency community is facing a new type of X account hijacking attack that can bypass two-factor authentication

Sep 26, 2025 11:24:45

Share to

ChainCatcher message, cryptocurrency developer Zak Cole disclosed that a new type of phishing attack is targeting the X (formerly Twitter) accounts of members of the crypto community. This attack disguises itself as an authorization request from the Google Calendar app, tricking users into granting full account control permissions. Attackers exploit the application authorization mechanism of the X platform, completely bypassing passwords and two-factor authentication.

MetaMask security researchers have confirmed that this attack is active in the wild. Users are advised to visit the connected apps page on X to check and revoke any suspicious "Calendar" app authorizations to ensure account security.

Recent Fundraising

More
$255M Mar 16
$21M Mar 16
-- Mar 13

New Tokens

More
Mar 11
Mar 8
Mar 4

Latest Updates on 𝕏

More
Mar 15
Mar 15
Mar 14