X logo

Addition SEC statement added below.

The X account for the U.S. Securities and Exchange Commission was hacked today to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.

The announcement came this afternoon in a now-deleted tweet from the SEC's hacked X account.

"Today the SEC grants approval to Bitcoin ETFs for listing on registered national security exchanges," read the fake X post.

"The approved Bitcoin ETFs will be subject to ongoing surveillance and compliance measures to ensure continued investor protection."

The tweet included an image of SEC Chairperson Gary Gensler with a quote promoting the alleged approval.

Fake ETF approval from hacked SEC account
Fake ETF approval from hacked SEC account

The news quickly spread, with many cryptocurrency and mainstream news sites covering the story and Bitcoin prices briefly spiking.

However, Bitcoin's jump in price was shortlived as it pulled back on news that the SEC's account on X was hacked to spread the fake news.

"The @SECGov twitter account was compromised, and an unauthorized tweet was posted," tweeted SEC Chairperson Gensler.

"The SEC has not approved the listing and trading of spot bitcoin exchange-traded products."

Gensler tweet

This was further confirmed by an SEC spokesperson who told BleepingComputer that the "unauthorized tweet regarding bitcoin ETFs was not made by the SEC or its staff."

BleepingComputer contacted the SEC with further questions about how they were breached and if 2FA was enabled on the account.

X has been overwhelmed by a massive wave of account breaches over the past month, as numerous verified organizations have been hacked to spread cryptocurrency scams and links to wallet drainers.

Yesterday, the Netgear and Hyundai MEA X accounts were hacked to promote fake cryptocurrency sites that stole cryptocurrency from wallets that connect to the Web3 site.

Web3 security firm CertiK was also hacked last Friday to promote a wallet drainer, and cybersecurity firm Mandiant was hijacked on Wednesday, even though it had two-factor authentication enabled.

In addition to account hijacks, threat actors have taken to X's advertising platform to create what feels like an endless stream of malicious advertisements promoting crypto scams and sites pushing wallet drainers.

Update 1/9/24 6:33 PM ET: While the SEC has not responded to our question about whether 2FA was enabled on the account, they sent BleepingComputer this additional statement.

"The SEC has determined that there was unauthorized access to and activity on the @SECGov x.com account by an unknown party for a brief period of time shortly after 4 pm ET. That unauthorized access has been terminated. The SEC will work with law enforcement and our partners across government to investigate the matter and determine appropriate next steps relating to both the unauthorized access and any related misconduct."

Related Articles:

Targus discloses cyberattack after hackers detected on file servers

Here's why Twitter sends you to a different site than what you clicked

Save $154 and get certified with this cybersecurity exam prep bundle

Save over $250 on these cybersecurity training courses

Save big on this in-depth ethical hacking course bundle — now just $46