+0.30%
+1.10%
+1.10%
+3.80%
+0.00%
+4.40%
The Same Script, Account After Account
The compromised accounts post nearly identical messages. They claim the account holder quietly invested in crypto and made enough to buy a new car. These posts often tag a coach identified as @coach_hannahrae and display a photo of a black Mercedes.
Victims often lose access and only discover the breach when followers start asking questions. The scam spreads because a crypto pitch from a known figure gains far more traction than the same pitch from a stranger.
How the Accounts Actually Get Taken
Hackers primarily gain access through phishing, not technical break-ins. The methods vary, but they all lean on the same weakness: trust.
- A direct message from an apparent contact asking the victim to vote in a competition through a malicious link
- Fake copyright violation emails designed to mimic official X communications, leading to a counterfeit login page
- SIM swapping, which intercepts one-time passwords sent by text
- Session hijacking, where malware steals a logged-in session token and bypasses passwords and two-factor authentication entirely
With the fake login page method, entering credentials and a two-factor code immediately logs the victim out, changes the account email, and hands control to the attacker before anyone notices.
Memecoins Made This Easier Than Ever
This surge in hacks follows a broader trend of crypto-related theft. April alone saw over $600 million stolen across nearly 30 incidents worldwide.
Platforms like Pump.fun, launched in 2024, have made it trivially easy to mint worthless tokens in minutes. That has fueled a wave of memecoins with no real project behind them, created solely for attackers to dump on buyers once the hype fades. Off-the-shelf phishing kits have made the account hijacking side just as simple.
X’s Crypto Lockout Promise Is Still Unproven
In April 2026, X’s then Head of Product, Nikita Bier, announced a system to automatically lock accounts the moment they post about cryptocurrency, requiring verification before allowing any crypto-related content through. Bier claimed this would kill 99% of the incentive for stealing accounts in the first place.
Bier left X in early August 2026. That leaves the rollout and actual effectiveness of the promised crypto lock unclear. The ongoing wave of hijacked Indian accounts suggests whatever protection exists isn’t stopping much yet.
What Actually Protects You Here
Security researchers advise moving beyond SMS-based two-factor authentication entirely. Authenticator apps, hardware security keys, or passkeys offer far stronger protection against SIM swaps and phishing, since these methods confirm you’re on the genuine site before ever logging you in.
Beyond that, the advice is simple: stay wary of unsolicited vote-for-me links in DMs or copyright violation emails, and never enter an X password on any page reached through a link.
Hashlytics Take
The pattern here says more about platform incentives than it does about hacker sophistication. None of these methods are new or particularly advanced. What is new is a promised fix that quietly lost its champion the moment its architect left the company. X announced a system specifically designed to kill the exact scam playing out right now, and months later there’s no public evidence it’s working or even fully live. That gap between announcement and accountability is where these scams keep finding oxygen.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



