Digital Asset News host warns of X account hacking wave and shares security steps
A solo presentation by the host of Digital Asset News on a wave of attempted X account takeovers and how to protect crypto accounts.
Summary
The Digital Asset News host describes receiving eight or nine password reset requests from X (formerly Twitter) in a single day, indicating a coordinated attempt to take over his account. He connects this to the broader rollout of X Money/X Payments, arguing that hackers are targeting X accounts specifically because of the financial functionality being added to the platform. He walks through a detailed set of security steps — covering Google Authenticator backup codes, passkeys, Gmail session reviews, and password reset protection on X — and warns that a compromised email account can render all other security measures useless. He also covers a separate threat: 19 malicious Chrome and Edge browser extensions caught draining crypto wallets and stealing seed phrases, affecting 80,000 users. The episode closes with brief market commentary, a note on Hyperliquid's potential Kraken partnership, and the permanent ban of former US Representative George Santos from the Kalshi prediction market platform.
Key Takeaways
FULL TRANSCRIPT
The X Account Hacking Wave
Host: The unthinkable happened — I almost got hacked yet again. And it looks like this is not going away as X and X Payments, or X Money, gets rolled out globally. This is what you need to do to protect yourself.
First, before we get into that — and I have to tell you it was pretty concerning, because I saw email after email showing hackers trying to reset my password — just a quick reminder: this Thursday, September 3rd, we'll be doing the 20-hour live stream trying to raise some funds for a local charity, the animal shelter here. We've got a lot of guests lined up. It's 20 hours and I need help providing some entertainment. At 6 in the morning we'll have Ivan on Tech, then Rob Art, then Wes, Nick from Coin Bureau, then of course Guy and Ben doing the NFA live show, Jerry Hall, Payton, your friend Danny, John Wang who's the head of crypto over at Kalshi, FD White's coming in, Dan from DB Crypto — and I have to tell you, Dan is entertaining, and if you do not know what's going on as far as hacks, Dan's your guy. We'll have Adrian Sontrius, who does a lot of different things with ozone therapy and all that. Robert Kiyosaki is more of a real estate guy. We'll get James Murphy, who is a lawyer and is going to talk a lot about the crypto space and Crux of Crypto stuff. And Jimmy Wong, Aaron Dishner, Randy Hipper will be there, and also a team from Kraken and Kalshi coming in to talk about things. It's going to be a pretty big show, and the whole thing of course is to raise funds for the local animal shelter, which I think is pretty important — because if not, they go to a kill shelter.
What Happened — Eight to Nine Hack Attempts in One Day
Anyhow, here's what we've got today. I woke up this morning, not really doing too much, just checking things out. And then I kept seeing this password reset request and I was like, "That's kind of interesting." Throughout the day I kept getting more of these X password reset requests. When you get these things and you look at them, you're like, "Oh, that's just a scam email, I'm not going to click on that." But then when you actually look at the email address it's from — which I did — it was from X.com. It was from the authentic site. So I was like, that's not too good. Looks like they tried four times, and then a couple of hours later they tried another four or five times. So roughly eight to nine attempts to hack into my account.
The thing is, if you don't have two-factor authentication turned on for your account — and also for your Gmail and your other email accounts — it's gone. It's going to be hacked. I just want you to know that if you follow anything on socials besides here on YouTube, be aware of what is being asked of you by these different public figures, because I can guarantee somebody got hacked and they're going to ask you for some funds, or to click on something, or maybe to download something. I don't want to get another email from people telling me they lost their entire life savings. You need to protect yourself. This is important.
Thanks to a shout-out to Jimmy for showing this to me — Guy on the crew over at Coin Bureau just released this, and I've been seeing it in my feed. A lot of people saying, "Hey, I got this, someone's trying to hack my account." X users are reporting a wave of attempted account takeovers and password resets today, with similar warnings flooding the timeline. I've seen this from a lot of different people, so it's not just me. The reason people are speculating this is happening is that as X Money rolls out — which I would love to be a part of, but I'm in Puerto Rico and they treat us like second-class citizens — the advice is: secure your account with two-factor authentication and password reset protection. Do not approve unexpected login requests or click unfamiliar links.
Why Hackers Target You — and How They Think
This is what the hackers are doing. And I have to tell you, hackers are the best investors out there. They don't have to do anything. They don't have to put in any money. They don't have to risk anything. All they have to do is make sure they catch you slipping. And once they catch that, they can download your passphrase, get your crypto, your Bitcoin, and they can do things like this as X Money gets rolled out — they can say, "Oh great, just send it to my account."
Step-by-Step: How to Secure Your X and Google Accounts
So how do you protect yourself? Guy on the crew did a pretty good breakdown. They say: enable your password reset protection. If you go into your profile and then into security and settings, there's an option there — Password Reset Protection — which will require you to confirm your email address or phone number to reset your X password.
Here's the problem. If your Gmail account has already been compromised, it doesn't matter — they've got your Gmail account, they'll just reset it. And this happens every single day. I've heard stories of hackers who have possessed someone's email account and just been sitting on it for six to nine months. This happened in a Coldcard scam — we all know about Coldcard. Someone got all their funds stolen, and one of the guys said, "Oh my god, I've got a Coldcard, I'm going to move this to an exchange until I figure this all out." He moved it to an exchange. Because his email was already compromised, the hackers were just waiting for him to move to that exchange, and then boom — they took all his Bitcoin. It was over a million dollars.
So be vigilant. These are the things you need to watch for.
Passkeys, Authenticators, and the Cloud Backup Problem
Now, this is what I recommend. Turn a passkey on. A passkey is like a Google Authenticator, and somebody — I forget who — put this in the comments and it was pretty good advice. They said the problem with Google Authenticator is that everybody uses Google Authenticator. You can use other authenticators that just give you a six-digit numerical value that changes every 10 to 15 seconds, and you can use something besides Google.
Here's the problem with Google Authenticator specifically: if you use Google Authenticator and have a Gmail account like I do, did you know that Google backs up your two-factor authenticator codes for emergencies? What that means is, if hackers have access to your email account, they can go into your email account, grab your two-factor authenticator emergency codes, and get into whatever they want — all your exchanges, all your accounts, all your socials.
So here's what you do. I've linked this in the description so you can go through the slides and do this correctly. When you're in your Gmail account, click on "Manage my Google account." Then click on "Security." From there, click "Review security tips." It's going to say "Turn on enhanced safe browsing" — continue or dismiss. Then what you want to do is review all your sign-ins. If you were in LA, in San Juan, in Texas — that makes sense. But if you've got something from Uzbekistan and you've never been there, make sure you shut that off.
Here's the big thing: remove access from your Google account to any apps you don't recognize. Go through that process. Then go back to the security tab and set up a passkey. With passkeys, you can create a sign-in to your Google account using your fingerprint. I personally use the biometric — my fingerprint — on my Mac. I use it all the time.
Then go back to the security tab and add an authenticator. This is the two-factor authenticator. And here's the issue — this is what the authenticator code looks like in your Google two-factor authenticator. They're set for 30 seconds. When you connect this to your exchange or to your Gmail account, there's a little cloud icon. You're going to click on that cloud and delete every single one of those codes, because those are the backups. You want to make sure you don't have any backups in the cloud, because all a hacker has to do is get into your Gmail account and go through all the steps I just showed you to retrieve them. Delete all those codes. Make sure there's no cloud backup for any of these codes. They should only live within the Google Authenticator app on your device.
If that went a little too fast, I apologize — there's a link in the description where you can go through it step by step and make sure you're protected.
19 Malicious Browser Extensions Draining Wallets
Unfortunately, it's not just that. This is from Keystone Hardware Wallet: be careful what you download. Nineteen Chrome and Edge extensions were caught draining wallets and stealing seed phrases. It's like we can't win. This is the same campaign from before, just bigger — it's been running for two years.
One extension alone hit 80,000 users. What these extensions do: they drain multi-chain wallets silently, they steal hardware wallet seed phrases, they grab credentials and browser history, and they push fake browser update pop-ups. As you may remember, my MetaMask wallet got hacked and I lost — well, I didn't lose a boatload of coins. Value-wise, they all sucked anyway. Except for one — that was a bummer. But it happened to me probably because I downloaded something stupid. So just be aware that these things are going on. Be very vigilant about what you actually download.
And of course, as always, if you're going to diversify your investments, please diversify how you do your security — iTrust, Kalshi, Ledger, ETFs. Not your keys, sometimes not your problems.
Positive News: Hyperliquid and Kraken
Let me change the pace a little bit and be positive. From Bloomberg: Hyperliquid is in advanced talks to bring its perpetual futures to US traders through Kraken's parent company, Payward. I find this interesting because Hyperliquid is one of those altcoins that actually has utility — it has a perpetual buyback program. If you were investing in Hyperliquid over the last year, you're up about 89%. Congratulations, Hyperliquid. I own a little bit but should have gone in heavier — here we are. When I get the guys from Kraken on Thursday, I'm going to ask them about this and what else they're doing. We might even talk about their IPO, which is coming through.
George Santos Permanently Banned from Kalshi
Lastly, before we get into the Q&A: Kalshi, which will also be on Thursday, did a good thing. They permanently banned former US Representative George Santos from trading on the platform and fined him $70,000, making it their first lifetime trading ban. If you don't know George Santos — he's super corrupt, and he was actually pushed out of Congress as well. What he did was bet on himself regarding whether he was going to attend President Donald Trump's State of the Union address, and he would play it back and forth and made a bunch of money. Of course, I'm sure he is the exception and not the rule, because congressmen and women are the best, most upstanding people and would never lie to us.
Tom Lee on the Four-Year Cycle and Year-End Outlook
Lastly, to bring it home — Tom Lee. He always comes with the good stuff. Here's what he says about the bear market, the four-year cycles, and how things are going. News flash: it's bullish. Let's take a listen.
Tom Lee: Robinhood was a breakout product launch — really one of the biggest hits. Agentic AI is good for crypto, but we were in the middle of that crypto winter. I do think catalysts have come together and are actually going to really strengthen into year-end. Because, one, crypto is the best-performing macro asset in the third quarter so far. So I think September and the fourth quarter there's going to be institutional allocation to crypto. The second is, the crypto four-year cycle basically ends next month. So I think people who've turned off crypto on their screens are going to come back.
Host: I have to agree with him. I think the people who turned off crypto are going to come back. I think the people who weren't into altcoins are going to start to speculate, and especially things are going to start to run up. And again, if you wonder why that actually happens, watch Saturday's video where I explained exactly why altcoins will run yet again. It really comes down to just speculation and a pinch of utility.
Q&A
That's it for today's main content. Let's get into the best part of the show — the Q&A. I'll answer all your questions to the best of my abilities.
Mullet says, "Come on, Rob. You have everything of value on iTrust. The most secure storage since Fort Knox. I sense sarcasm. The dust you have floating around isn't worth stealing." And I responded, "Hey, they could get my Trump and Melania coins." That's where I put all my valuations. That's just a joke.
John Wang will be on Thursday. Yeah, it's going to be good times.
Delta says you can disable that — that's right, you should probably delete the Google account recovery codes. So that would look like this: when you have the backup codes, if you see this and you don't have any codes that hackers can steal, the bad news is if you lose your phone that has your authenticator app, it's a real pain to go to every account. And that's another thing — if you lose your authenticator app and you want access back to Kraken or whatever exchange you're using, it's a real pain to get it back. You have to submit a lot of documentation. But I would rather do that than log into my account and see all my crypto's gone. So delete the backup codes — that's how you want to do it. Only the paranoid will survive. That's pretty much what it comes down to.
Chris says, "I wouldn't trust Windows with banking and definitely not crypto. I never have and never will access any finances on my Windows PC. Call me paranoid." Not paranoid. Probably one of the few people that will make it out alive. Again, it's not how much we make, it's how much we keep. And it's very hard to keep our hands on the things we keep because we keep getting scammed and screwed over. It's a real problem.
Doc says he got Hyperliquid at $29. How is the market doing today? I don't really check it anymore. Let's see — we're down to $77,000 for Bitcoin. What a bummer. Tron's down a lot, 3%. And Hyperliquid is up 89% over a year. Take a look at the max chart — that's a nice chart. Went from $6, pumped to $28 in 2024, and then just a nice run. And it's ranked number 10. They kicked Dogecoin out of the top 10. Cardano's still in the top 20 — that's crazy.
Someone asks what products I'd highlight in the RWA and agentic narrative. Well, we can take a look at RWA.xyz. These are the things being tokenized: treasury debt, commodities, strategy, stocks, and so on. As far as what is being placed on said networks, Ethereum is still leading the charge at $17 billion, 41 million for 9,048 assets. Then comes Binance, Solana, Stellar, Avalanche, Hyperliquid. So I've got three of the four of what I'd call the best — Binance, Ethereum, Solana. Tron is not a part of this; Tron is more for payments. As far as agentic moves, Polygon could be one of them. These layer-twos could be one, but I'm not too sure about agentic specifically. I know Base is pushing in, and that's Coinbase's centralized layer-2 solution. I haven't really kept up too much with the agentic issues so far.
TTK says fake BIP-10 apps and emails will scam plenty of newbies out of their Bitcoin, claiming urgent action is needed. And of course all the AI bots that are out there are going to run and become smarter and smarter and really socially engineer a lot of account draining. I think that's the way it's going. Again, it's not like they have to hack you — they're just waiting for you to come to them. Just a little bit of bait on a line and then you do all the work and transfer it all to them. That's the problem.
Kappo says we're probably still due for a big pullback. I hope you're right, Kappo — especially if you could orchestrate that on Monday at 5:00 a.m., that'd be fantastic. That way I have an hour and a half to figure out how much I'm going to dump into Bitcoin.