Account thieves pivot to X as a credential front door for crypto drainers
A new wave of account-takeover messages is bypassing passwords to reach inboxes, and the downstream target is the holder's crypto wallet.

At 06:00 UTC on 19 July 2026, the consumer-fraud beat published a familiar warning dressed in new clothes. The subject line read: "We noticed a login from a new device." The sender, however, was not X. It was a phishing kit dressed up as X's own security alert, designed to harvest the password of an account whose owner may have been on the platform since the Twitter era, then pivot that credential toward crypto theft.
The pivot is the story. Account takeovers on X, the platform renamed from Twitter in 2023, are not new. What has changed is the conversion rate from "stolen login" to "empty wallet," and that change is concentrating the criminal industry's attention on a single front door. The email pretending to be a security notice is a credential-grabber; the credential is the key to a verified handle; the handle is the launchpad for a fake token, a counterfeit airdrop, or a direct-message phishing campaign aimed at a target's followers. By the time a victim realises their password has been rotated, the damage has moved one layer down the stack, into a custody wallet or a CEX account.
The shape of the new lure
The pattern that surfaced this week is a copy of X's own password-reset and device-verification emails, sent from a look-alike domain. The recipient is invited to confirm a login from a device they do not recognise, on the rationale that doing so will secure the account. The link resolves not to x.com but to a typosquatted host that captures the credentials and, in many observed variants, the session cookie.
Once the attacker owns the handle, the playbook forks. In the more visible branch, the account posts a "launching a new token" announcement, attaches a contract address, and watches the chain. In the quieter branch, the attacker reads the direct-message history for any conversation that mentions a wallet address, then re-enters that conversation as the trusted party. The second branch is harder to detect and yields less attention, but its conversion economics, on a per-account basis, are reportedly stronger.
The phishing kit is a commodity. So are the resale channels for verified handles. So, increasingly, are the laundering rails for the proceeds. What is new is the tight integration between the three: a credential captured this morning can fund a fake-token launch this afternoon, with the wallet emptied before the original owner has finished their coffee.
Why the conversion rate is climbing
Three structural shifts are stacking. First, X's two-factor authentication, when it is enabled at all, is overwhelmingly SMS-based, which is precisely the channel most exposed to SIM-swap attacks. Second, the platform's verification marks, blue and otherwise, function as a trust signal that compresses the time a victim spends on due diligence. Third, the cost of standing up a convincing impersonation campaign has collapsed, because the off-the-shelf kits now bundle the email lure, the domain, and the chain-side drainer in a single subscription.
That bundle is what makes the economics work. A phisher who a decade ago needed a custom front-end, a money-mule network, and a separate Bitcoin laundering step now needs a subscription fee and a list of high-value handles. The handle, not the user, is the product. Crypto gives the attacker a settlement rail that does not pause for a chargeback.
The counter-frame: hygiene, not panic
The defensive reading is that most of these attacks still depend on a user clicking through a fake domain. Enabling a hardware security key, or at minimum an authenticator-app code rather than SMS, closes the credential-grab vector. The platform has, over the past year, leaned into passkey enrolment for high-value accounts, and the rate of takeovers among enrolled handles has reportedly fallen. The constraint is human: the population most likely to be phished is the population least likely to have rotated to a phishing-resistant second factor.
A second, less comfortable counter-frame is that some of the visible losses are downstream of earlier attacks the user has already forgotten. The "new device" email often arrives at an address the user no longer monitors; the credential captured is one the user rotated months ago. The attacker is fishing a stale pond. That makes the fix cheap, in principle, and socially hard, in practice.
Stakes
If the pattern holds, the next twelve months will see the criminal industry's centre of gravity shift further from exchange-front-door exploits toward identity-layer exploits on the platforms where crypto audiences already gather. The handles worth the most are not the celebrity accounts; they are the working analysts, the project founders, and the customer-support staff at the exchanges themselves. A single password reset on the right handle is worth more than a thousand generic phish.
Two things to watch. First, whether the major wallet providers begin to flag or quarantine inbound transactions from handles that have demonstrably rotated credentials within the previous 48 hours. Second, whether the platform itself tightens its own device-verification emails, because the easiest fix is not a user habit but a sender policy the platform can publish tomorrow.
Desk note: Monexus has not relied on any single outlet's framing here. The thread material is the 19 July consumer-fraud piece on the phishing email pattern; the second thread item (a Polish-language X post about a building dispute) has been ignored as off-topic. The article's structural reading rests on the credential-to-wallet pivot described in that single source, and is silent where the source is silent.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/premiumpromotion/