Blockchain security firm CertiK’s main X (Twitter) account was compromised in early January 2024 and used to post a fake security alert claiming a critical Uniswap router contract vulnerability, instructing users to ā€œrevoke approvalsā€ via a link that impersonated Revoke.cash. The link led to a phishing site/wallet drainer designed to steal users’ funds, not to the real Revoke.cash service. Shortly after the message went live, the legitimate Revoke.cash account publicly warned that CertiK’s X account had been hacked and that the Uniswap exploit warning and Revoke link were fraudulent, stressing that Uniswap was not compromised. CertiK later explained that the breach stemmed from a social-engineering phishing attack: an employee interacted with a Calendly-style scheduling link sent by a hacked account posing as a media representative (reported as a Forbes-related account), which harvested credentials and allowed the attacker to hijack CertiK’s X profile. The malicious posts were detected and removed within minutes, and CertiK said its investigation indicated no significant losses and that the incident was part of a broader, ongoing campaign targeting multiple Web3-related accounts via similar social engineering techniques. The episode highlights how even security-focused firms can be used as high‑credibility lures in phishing operations and underscores the need for users to verify security alerts and URLs—especially when posts claim urgent vulnerabilities and direct them to ā€œrevokeā€ permissions or secure assets through unfamiliar links.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $LINK

Comments