"We noticed a login from a new device": how X account hijacks are feeding crypto's scam economy
A routine email about a new-device login has become the first move in a credential-theft economy that ends in drained wallets and hijoked influencer accounts.

The email looks legitimate enough to ignore. Sent from a domain that resembles X's own, it tells the recipient, a long-time account holder who joined back when the platform was still called Twitter, that "we noticed a login from a new device". The message is a lure. Clicking the link inside drops the user onto a convincing replica of X's login page, where the password is captured and then weaponised. From there, the account is either sold, used to push a token, or quietly turned into a launchpad for the next round of phishing.
This is the operating logic of the modern credential-theft economy, and crypto is its most lucrative downstream market. Stolen X accounts do not just embarrass their original owners; they are inventory. A verified handle with years of history and a network graph of crypto contacts is worth more than a fresh disposable account because it inherits trust. Theft has migrated up the stack, from random phishing of email inboxes to the deliberate targeting of the social handles that the crypto industry has built its marketing apparatus on top of.
The bait, restated
The "new device" email is a low-cost, high-yield tool. It works because X genuinely does send the same kind of notification when a user signs in from an unfamiliar phone or browser, so the fraudulent copy blends into a real stream of platform messages. The article that surfaced the pattern at 06:00 UTC on 19 July 2026 walks through the playbook in plain terms: a fake login page captures the password, the attacker pivots to whatever is reachable from the compromised account, and the original holder is locked out before they notice.
The downstream use case is rarely ideological. It is financial. Compromised handles are rebranded to impersonate founders, VCs, or trading desks; a pinned post promoting a contract address can move six figures before the original owner regains control, if they ever do. Industry observers have spent two years flagging this pattern, and the surface keeps growing because the reward side compounds while the friction on the defence side barely moves.
Why crypto, specifically
Crypto's plumbing is what makes the hijack-to-scam pipeline so efficient. A wallet address can be pasted into a tweet and a victim can be on-chain in under a minute. There is no chargeback rail, no fraud team at the receiving end, and almost no friction between a malicious post and a signed transaction. By contrast, draining a compromised bank account requires either a money-mule layer or an ACH reversal, both of which leave audit trails. Theft on X followed by a drain on-chain leaves almost none.
This asymmetry has reshaped which accounts attackers want. Three years ago the priority list was high-follower general-interest handles, because they monetised through ad-account resale and spam blasts. The list today is dominated by accounts with a credible crypto footprint: a founder's dormant-but-credentialed identity, a VC's verified handle, an analyst's long-tail audience. The signal an attacker looks for is not raw follower count; it is proximity to on-chain capital.
What the platform owes its users
X has spent more than a year talking about tightening direct-message controls and rolling out hardware-key requirements for high-value accounts. The talk has not translated into a noticeable drop in the credential-theft problem. Passkeys and phishing-resistant authentication have been available on the platform for some time, but uptake among ordinary users remains low because the rollout has been treated as a feature, not as a default.
That distinction matters. The platforms on which the crypto industry has built its public face were never designed as financial infrastructure, and they have been reluctant to accept the burden that comes with that role. A social network whose users send billions of dollars a year to addresses pasted in its posts has, in effect, become a payments-adjacent surface, and the security posture that was adequate for opinion-sharing is not adequate for that role. Until passkeys or hardware-key second factors become the default rather than the opt-in, the credential-theft economy will keep harvesting the same crop of handles.
What users can do in the meantime
The defensive moves are unglamorous and well known, and most users have not made them. The first is to enroll a hardware security key or a passkey as the primary second factor, and to retire SMS codes entirely. SIM-swap attacks are still routine, and SMS is the weakest of the available factors. The second is to treat any "new device" notification as a prompt to open the app directly rather than to click any link inside the email; the path to verify is to navigate to the platform's settings, not to follow a link the email provides.
The third, and the one the industry needs to internalise, is to assume that any X account, however verified or senior, is a credential and not an identity. Treat handles the way a bank treats a SWIFT code: a routable address whose compromise is recoverable, not a statement about the underlying person. Funds should sit behind hardware wallets, custody providers, or multisigs that do not depend on the integrity of any single social-media account. The platform is a marketing surface. It is not a vault.
The honest ledger
What this analysis can verify from the available reporting is narrow: the "new device" lure is being used to phish X credentials, and the intended downstream use is financial fraud, with crypto scams a recurring case study. The reporting does not specify how many accounts have been compromised in this campaign, which particular groups are running it, or what share of stolen credentials end up routed into wallet drains versus other fraud. The platform's published mitigation metrics are also absent from the source material; claims about the scale of the response should wait for primary disclosures.
What remains worth saying out loud is that the gap between the platform's stated authentication roadmap and the user's working assumption about safety is, today, the single biggest enabler of the credential-theft economy. Closing that gap is a policy choice, not an engineering limit. Until the choice is made, the inbox will keep getting the same polite email, and a meaningful share of recipients will keep clicking.
Monexus framed this as a credential-theft story with crypto as the main downstream market, rather than as a crypto-native fraud story; that ordering matters because the security failure sits upstream of the on-chain drain.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/cluster-9093cc59c0
- https://en.wikipedia.org/wiki/Passkey_(authentication)