MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Advanced X account takeover attack now targeting the crypto community
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,581.00-0.85%
  • ethereumEthereum(ETH)$2,314.47-0.86%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.44-0.17%
  • binancecoinBNB(BNB)$637.34-0.35%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$86.390.33%
  • tronTRON(TRX)$0.323785-1.71%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.042.62%
  • dogecoinDogecoin(DOGE)$0.0983590.84%
Crypto NewsBlockchain

Advanced X account takeover attack now targeting the crypto community

rahulbadiyafad150c105
Last updated: September 25, 2025 4:57 pm
rahulbadiyafad150c105
Published: 7 months ago
Share

A new, sophisticated phishing campaign is targeting the X accounts of crypto personalities, using methods that bypass two-factor authentication and appear far more convincing than traditional scams.

Contents
  • How the phishing works
  • The clue that exposes the attack

Crypto developer Zak Cole reported in a Wednesday X post that the campaign exploits X’s own infrastructure to hijack accounts. “Zero detection. Active right now. Full account takeover,” he warned.

Unlike typical phishing attacks, this campaign does not rely on fake login pages or password theft. Instead, it abuses X’s application support system to gain account access while circumventing two-factor authentication.

MetaMask security researcher Ohm Shah confirmed seeing the attack “in the wild,” indicating a broader campaign, while a less sophisticated version also targeted an OnlyFans creator.

How the phishing works

The attack’s sophistication lies in its credibility and subtlety. It begins with an X direct message containing a link that appears to lead to the official Google Calendar domain, exploiting how the platform generates link previews. In Cole’s case, the message was disguised as coming from a representative of venture capital firm Andreessen Horowitz.

The message links to the domain “x(.)ca-lendar(.)com,” which was registered just last Saturday. However, X displays the legitimate calendar.google.com in its preview, exploiting how the platform generates previews from site metadata.

“Your brain sees Google Calendar. The URL is different.“

When users click the link, the page’s JavaScript redirects them to an X authentication endpoint, requesting authorization for an app to access their account. The app appears as “Calendar,” but a technical analysis shows its name includes two Cyrillic characters resembling “a” and “e,” making it a different app from X’s legitimate “Calendar” application.

The clue that exposes the attack

The clearest early warning may be the URL, which flashes briefly before the redirect—so short that many users could easily miss it.

A more obvious red flag appears on the X authentication page itself. The app requests an extensive list of permissions, including following and unfollowing accounts, updating profiles and account settings, creating and deleting posts, interacting with others’ posts, and more. Such broad access is clearly unnecessary for a calendar app and can alert cautious users to the phishing attempt.

If granted, the attackers gain full account control, with a further hint revealed as users are redirected to calendly.com instead of Google Calendar.

“Calendly? They spoofed Google Calendar but redirect to Calendly? That’s a major operational security failure. This inconsistency could tip off victims,” Cole noted.

Cole’s GitHub report on the attack recommends that users check their X connected apps page to see if their account may have been compromised. He advises revoking any app named “Calendar” to remove potential unauthorized access.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Trump to designate cryptocurrency a national priority, reports say | ForkLog
Three-Year Dollar Low Fuels Crypto Surge- Bitcoin Eyes $130 – Crypto News Flash
Bybit Launches ETH Trading Competition With 100,000 USDT Prize Pool
Lack of scrutiny exposed as fake Hyperliquid app pops up on Google Play Store – Cryptopolitan
A win-win-win outcome for the crypto market structure bill: Coinbase CEO Brian Armstrong | FXStreet
TAGGED:AdoptionAltcoinBlockchainBusinesscryptocurrenciesCybersecurityHacksPhishingScamsTwitter

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Should You Buy Nio Stock While It Trades Around $7?
Next Article Should You Buy Nio Stock While It Trades Around $7? | The Motley Fool
© Market Alert News. All Rights Reserved.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Prove your humanity


    Lost your password?

    %d