Connect with us

Crypto

Mandiant X/Twitter hacker linked to $900K cryptocurrency phishing scheme

Published

on

Mandiant X/Twitter hacker linked to 0K cryptocurrency phishing scheme

Mandiant, a Google-owned cybersecurity company, says a “brute force password attack” likely caused the takeover of its X (formerly known as Twitter) account last week.

The account hijacking was part of a cryptocurrency phishing campaign linked to a drainer-as-a-service (DaaS) offering Mandiant calls CLINKSINK, according to a blog post detailing the company’s investigation.

An estimated $900,000 or more in Solana (SOL) cryptocurrency has been stolen in recent campaigns by 35 CLINKSINK affiliates identified in the Mandiant probe. These affiliates typically share about 20% of the stolen crypto with the DaaS operator, who raked in more than $180,000 in SOL since New Year’s Eve, according to the blog post.

Meanwhile, Mandiant is facing scrutiny after admitting that “some team transitions and a change in X’s 2FA policy” resulted in the security lapse that led to the hijacking.

Mandiant is one of several well-known organizations caught up in a recent string of X account hijackings, which most recently hit the U.S. Securities and Exchange Commission (SEC) in an incident that briefly shook up the Bitcoin market. 

Advertisement

Mandiant’s X/Twitter hack explanation, 2FA lapse questioned by critics

Mandiant noted in its blog post that no Mandiant or Google Cloud systems, other than its X account, were compromised in the hours-long incident on Jan. 3.

Referring to a likely “brute force” attack, the company’s statements published on X Wednesday afternoon seem to imply an attacker targeted the social media account by trying multiple passwords until they successfully logged in.

In replies to Mandiant’s post, some critics noted that this explanation was questionable due to X’s policy of temporarily locking accounts after a “limited number of failed attempts” to log in.

“Not possible due to rate limitation except if the password was 123Password,” one user commented.

The exact number of failed attempts needed to trigger this measure is not provided by X, so SC Media tested the log in feature on a personal X account. We received a notice that the account was locked on the sixth attempt to log in with the wrong password.

Advertisement

No alerts about the failed log-in attempts were sent to the email address linked to the account, and we were also able to access the account, during the temporary lock out period, using the option to sign in with Google/Gmail.

Mandiant did not elaborate on the two-factor authentication (2FA) policy change that contributed to the breach, but this likely refers to X’s removal of the SMS 2FA option for non-Premium subscribers on March 20, 2023.

If this is the case, Mandiant’s account likely had no 2FA protection when it was compromised. X users can still use the authentication app or security key methods of 2FA for free.

“We’ve made changes to our process to ensure this doesn’t happen again,” Mandiant said in its statement.

A Google spokesperson declined to provide additional details about the incident to SC Media.

Advertisement

CLINKSINK affiliates impersonate legitimate crypto sites to drain wallets

After compromising Mandiant’s X account, which has more than 123,000 followers, the hijacker changed the account handle to @phantomsolw, impersonating the legitimate Phantom crypto wallet.

In a post on the hacked account, the CLINKSINK affiliate promoted a supposed opportunity to claim free $PHNTM tokens by clicking a link. Upon clicking the link, users would be urged to connect their Solana wallet and sign a transaction to claim the promotional token airdrop.

The JavaScript-based CLINKSINK drainer linked to the phishing site performs checks to verify that victims have the Phantom Desktop Wallet installed and is capable of surveying connected Solana wallets to check details, including balances. CLINKSINK is also set up to split the drained funds between the affiliate and operator accounts, usually at a ratio of 80% and 20%, respectively.

In the case of the Mandiant hijacking, the phishing scheme failed due to Phantom recognizing the site as malicious and blocking users from connecting their wallets, BleepingComputer reported.

The hijacker later deleted the phishing tweet and resorted to using the Mandiant account to mock the company with messages like “Check bookmarks when you get your account back.”  

Advertisement

Mandiant identified other legitimate crypto utilities like DappRadar and BONK being used in related CLINKSAFE campaigns across social media platforms, including X and Discord.

CertiK, Netgear and Hyundai Middle East & Africa (MEA) have also had their X accounts hacked in cryptocurrency-draining schemes this year, but there is no confirmation that these incidents were also linked to CLINKSINK.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Crypto

The Best Cryptocurrency to Buy with $1,000 Right Now | The Motley Fool

Published

on

The Best Cryptocurrency to Buy with ,000 Right Now | The Motley Fool

As long as the price of gold continues to soar, gold-backed stablecoins will remain an attractive investment opportunity.

It’s been a dismal year for the crypto market. Bitcoin (BTC +1.62%) is down 25% for the year, while Ethereum (ETH +2.07%) is down 36% (as of Feb. 19). With these two market bellwethers struggling to find their footing, almost no major cryptocurrencies are in the green.

But there is one sector of the crypto market that is booming right now: gold-backed stablecoins. The two leaders here are Tether Gold (XAUT +0.33%) and PAX Gold (PAXG +0.25%). Together, they account for 90% of the gold-backed stablecoin market. If you’re looking to put $1,000 to work in the crypto market right now, this could be a good place to start.

Tether Gold or PAX Gold?

It can be tough making the choice between Tether Gold and PAX Gold. Both are pegged 1-to-1 to the price of physical gold, and both are up 15% for the year. Both now rank among the top 35 cryptocurrencies in the world, and both have market caps of roughly $2.5 billion.

Image source: Getty Images.

Advertisement

But PAX Gold has one clear advantage over Tether Gold: it is fully regulated by U.S. banking authorities, and is generally more accessible than Tether Gold for U.S. investors. For that reason, PAX Gold gets my vote over Tether Gold. For a total cost of $1,000, you can pick up about 0.2 tokens at today’s prices.

Physical gold, Bitcoin, or tokenized gold?

A year ago, some investors touted Bitcoin as digital gold. It was presumed to be the one safe asset that you needed to have in your crypto portfolio. These enthusiasts considered it just as valuable and appealing as physical gold. But during the past 12 months, the prices of Bitcoin and physical gold have radically diverged, and that’s leading investors to question the digital gold investment thesis.

PAX Gold Stock Quote

Today’s Change

(0.25%) $12.54

Current Price

$5037.08

Advertisement

During the past 12 months, gold is up a head-spinning 71%, while Bitcoin has taken a serious hit in value. For that reason, money has now been flowing into gold-backed stablecoins. At the end of 2025, this was a $4 billion market opportunity. Just two months into 2026, it’s now a $5 billion market opportunity. As long as the price of gold continues to climb, so will the demand for gold-backed stablecoins.

Investors now have several different ways to get their gold exposure. They can buy physical gold bars. They can invest in gold exchange-traded funds (ETFs). And now they can invest in tokenized gold in the form of stablecoins.

Advertisement

Investors in PAX Gold can exchange their tokens at any time for physical gold, just as owners of dollar-pegged stablecoins can exchange their tokens for physical dollars at any time. Think of it as owning the right to pick up physical gold at any time, without all the worries of actually owning physical gold bars.

At a time when nearly all major cryptocurrencies are trending down, there are few safe spots to park your money in the crypto market right now. That’s why I’m keeping my eye on tokenized gold as a potential investment opportunity in 2026.

Continue Reading

Crypto

Wisconsin bill targets cryptocurrency kiosk scams

Published

on

Wisconsin bill targets cryptocurrency kiosk scams

The Wisconsin Assembly passed a bill that aims to rein in cryptocurrency scams, creating new consumer protections around kiosks that can be found at gas stations and convenience stores. 

What they’re saying:

Criminals are known to trick victims into depositing money into the kiosks under the guise of protecting their money or paying a fine. Once the money is sent, it’s almost impossible to get back.

Advertisement

FREE DOWNLOAD: Get breaking news alerts in the FOX LOCAL Mobile app for iOS or Android

The amended bill that passed Thursday sets a daily transaction limit of $1,000 per person. AARP Wisconsin said the bill protects against large-scale losses.

Advertisement

“We know these are essentially major scam machines, and while they look like a regular bank ATM, they are not,” said AARP’s Erin Fabrizius. “People are being directed there under duress.”

What’s next:

The bill now heads to the Wisconsin Senate.

Advertisement

The Source: FOX6 News reviewed the bill and referenced information from AARP Wisconsin.

PoliticsNewsWisconsin
Advertisement
Continue Reading

Crypto

After $3T crypto volume in 2025, CME plans 24/7 regulated trading

Published

on

After T crypto volume in 2025, CME plans 24/7 regulated trading

CHICAGO, Feb. 19, 2026 /PRNewswire/ — CME Group, the world’s leading derivatives marketplace, today announced that its regulated Cryptocurrency futures and options will be available for trading 24 hours a day, seven days a week beginning on May 29, pending regulatory review.

“Client demand for risk management in the digital asset market is at an all-time high, driving a record $3 trillion in notional volume across our Cryptocurrency futures and options in 2025,” said Tim McCourt, Global Head of Equities, FX and Alternative Products at CME Group. “While not all markets lend themselves to operating 24/7, providing always-on access to our regulated, transparent Cryptocurrency products ensures clients can manage their exposure and trade with confidence at any time.”

Beginning Friday, May 29 at 4:00 p.m. CT, CME Group Cryptocurrency futures and options will trade continuously on CME Globex with at least a two-hour weekly maintenance period over the weekend. All holiday or weekend trading from Friday evening through Sunday evening will have a trade date of the following business day, with clearing, settlement and regulatory reporting processed the following business day as well.

Cryptocurrency futures and options continue to reach record volumes at CME Group in 2026. Year-to-date highlights include:

  • Average daily volume (ADV) of 407,200 contracts, up 46% year-over-year, and average daily open interest of 335,400 contracts, up 7% year-over-year
  • Futures ADV of 403,900 contracts, up 47% year-over-year

As the world’s leading derivatives marketplace, CME Group (www.cmegroup.com) enables clients to trade futures, options, cash and OTC markets, optimize portfolios, and analyze data – empowering market participants worldwide to efficiently manage risk and capture opportunities. CME Group exchanges offer the widest range of global benchmark products across all major asset classes based on interest ratesequity indexesforeign exchangecryptocurrencies, energyagricultural products and metals.  The company offers futures and options on futures trading through the CME Globex platform, fixed income trading via BrokerTec and foreign exchange trading on the EBS platform.  In addition, it operates one of the world’s leading central counterparty clearing providers, CME Clearing. 

CME Group, the Globe logo, CME, Chicago Mercantile Exchange, Globex, and E-mini are trademarks of Chicago Mercantile Exchange Inc.  CBOT and Chicago Board of Trade are trademarks of Board of Trade of the City of Chicago, Inc.  NYMEX, New York Mercantile Exchange and ClearPort are trademarks of New York Mercantile Exchange, Inc.  COMEX is a trademark of Commodity Exchange, Inc. BrokerTec is a trademark of BrokerTec Americas LLC and EBS is a trademark of EBS Group LTD. The S&P 500 Index is a product of S&P Dow Jones Indices LLC (“S&P DJI”). “S&P®”, “S&P 500®”, “SPY®”, “SPX®”, US 500 and The 500 are trademarks of Standard & Poor’s Financial Services LLC; Dow Jones®, DJIA® and Dow Jones Industrial Average are service and/or trademarks of Dow Jones Trademark Holdings LLC. These trademarks have been licensed for use by Chicago Mercantile Exchange Inc. Futures contracts based on the S&P 500 Index are not sponsored, endorsed, marketed, or promoted by S&P DJI, and S&P DJI makes no representation regarding the advisability of investing in such products. All other trademarks are the property of their respective owners. 

Advertisement

CME-G

 

View original content:https://www.prnewswire.com/news-releases/cme-group-to-launch-247-cryptocurrency-futures-and-options-trading-on-may-29-302692346.html

SOURCE CME Group

Advertisement
Continue Reading

Trending