X-based NFT phishing attack causes losses of over $691,000

Malicious actors targeted Ethereum co-founder, Vitalik Buterin, to spread the phishing attack

Add bookmark
A golden Ethereum coin placed on a golden computer mainboard

A phishing attack has led to the loss of over US$691,000 following the compromise of the X (formerly Twitter) account of co-founder of decentralized blockchain Ethereum and cryptocurrency Ether, Vitalik Buterin.

The hack was discovered on September 9, following suspicious activity on Buterin’s X account. After compromising Buterin’s account, the hackers attempted to steal cryptocurrency and NFTs from those who followed the Ethereum co-founder on X, by making a post which offered a free commemorative NFT to them to “celebrate Proto-Danksharding coming to Ethereum”. Instead, this post contained a phishing link that required victims to link their blockchain wallets to the phishing site before receiving the NFT, allowing malicious actors to drain victim’s wallets.  

Buterin’s father, Dmitry Buterin, warned Vitalik’s followers that the post and link were not legitimate via a post on X which read: “Apparently Vitalik has been hacked. He is working on restoring access”.

Despite the warning, the post did lead to the victimization of some of Vitalik Buterin’s network, including Ethereum developer, Bok Khoo, who warned others not to interact with the malicious post after losing “a few” of his CryptoPunks NFTs.

ZackXBT posted updates regarding the attack to his X account, noting that as of September 10, $691,000 in cryptocurrency and NFTs had been stolen by the malicious actors. 

It is currently unknown how hackers gained access to Buterin’s account and whether he was the victim of a similar phishing link. It has been suggested, however, that he was the victim of a SIM-swap cyber attack. SIM-swap attacks see malicious actors take control of a victim’s phone number by porting it onto SIM card in their possession. Once they have control of the phone number, malicious actors can bypass two-factor-authentication efforts which send one-time-passcodes via SMS to the victim’s phone.

In the case of Buterin, this would allow hackers to reset his X account’s password, allowing them to log in and post the malicious link.

One of Buterin’s followers, who uses the screenname satoshi_767, criticized Buterin for being compromised in this way, saying that he “should take accountability for his poor [operational security] and compensate those affected”.  

They continued, saying: “The only way this isn’t negligence on Vitalik part is if someone at X internally compromised the account, or if he was coerced in person by a criminal who threatened violence. I highly doubt that’s what happened.”

They finished by saying they hope an investigation into the cyber attack is launched to help victims better understand how it took place. 
ZackXBT disagreed with satoshi_767’s assertions, saying: “You do not know yet whether it was a SIM swap. Vitalik is a big enough target to where an insider could have been paid off or panel was used.”

ZackXBT, however, did agree that Buterin should compensate those who fell victim to the phishing link if it was confirmed that he was the victim of a SIM swap attack, as “that would be his fault for using SMS 2FA”. ZackXBT did not that he is sure that Buterin does not use these cyber security methods, and stressed that he should not be held accountable for something that was “entirely out of his control”. 


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62d96c67be966e20ca4a6713","name":"IOTW: FBI warns fake cryptocurrency apps have defrauded investors of $42.7m","description":"The FBI has warned cryptocurrency investors to avoid fraudulent apps that may initially appear legitimate","file":null,"url":"\/iot\/news\/itow-fbi-warns-fake-cryptocurrency-apps-have-defrauded-investors-of-427m"},{"id":"63d9047f20fdc1756c1e8d8c","name":"Why do hackers target cryptocurrencies?","description":"Cryptocurrency investors continue to be a target for cyber attacks, Cyber Security Hub investigates why","file":null,"url":"\/attacks\/articles\/why-do-hackers-target-cryptocurrencies"},{"id":"635beb34ff52524cd3692935","name":"Hacker steals US$1mn worth of crypto and NFTs in 24 hours","description":"The hacker used phishing attacks to steal the cryptocurrency during the spree","file":null,"url":"\/attacks\/news\/hacker-steals-us1mn-worth-of-crypto-and-nfts-24-hours"},{"id":"62f129ac52b3812f2a26d541","name":"Nomad offers $19m bounty for stolen crypto","description":"Cryptocurrency firm Nomad has reported a loss of $190m following a bridge hack and has offered a bounty to \u2018white hat\u2019 hackers who can return it","file":null,"url":"\/attacks\/news\/nomad-offers-19m-bounty-for-stolen-crypto"},{"id":"5b36763997533d1a8a6f6da5","name":"\u2018The Rise Of Crypto-Miners\u2019: Q&A With CyberArk\u2019s Shay Nahari","description":"Topics: Red Teaming, Threat Landscape & More","file":null,"url":"\/security-strategy\/news\/the-rise-of-crypto-miners-qa-with-cyberarks-shay-nahari"}],"featured_content_portal_embedded":null}" >