OpenAI's Official X Account Hijacked for Cryptocurrency Scam: A Lack of Two-Factor Authentication?
In a surprising turn of events, OpenAI's official account on X/Twitter was hijacked by hackers, targeting the renowned @OpenAINewsroom account (currently with 54K followers) to promote a cryptocurrency scam.
After the hacker hijacked the account, he posted the following message:
We are very excited to announce the launch of $OPENAI, a token that bridges the gap between artificial intelligence and blockchain technology. All OpenAI users are eligible to receive $OpenAI tokens, which will provide access to all of our future testing programs.
The fraudulent post directed users to a phishing site (hxxp://token-openai.com), urging them to connect their cryptocurrency wallets. Unfortunately, once connected and authorized, the hackers would transfer out all assets within minutes.
After a while, OpenAI, possibly alerted by feedback, regained control of the account and deleted the misleading posts. However, it's likely that many followers of OpenAINewsroom fell victim to the phishing and lost cryptocurrency.
So far, neither OpenAI nor OpenAINewsroom has issued a statement regarding the incident, leaving the method of account hijacking unclear. Drawing parallels with a previous SEC account hijacking, it's speculated that the lack of two-factor authentication, a password leak, or a SIM swap attack on the account operator's mobile number could be the culprits.