New York’s Department of Financial Services issued subpoenas on July 17, 2020, and surveyed regulated cryptocurrency companies about their response to the Bitcoin scam conducted through compromised Twitter accounts, according to the department’s subsequent investigation report.
The regulatory action followed New York Governor Andrew Cuomo’s July 16 request for an investigation into the breach. It extended the inquiry beyond Twitter’s internal security failure to a practical question for the digital-asset industry: how quickly could exchanges and hosted-wallet providers recognize a fraudulent Bitcoin destination and stop customer transfers?
The subpoenas were not publicly detailed on July 17. The department’s later report supplies the exact chronology. Contemporaneous reporting established that the FBI was also investigating and that Twitter had identified approximately 130 targeted accounts while it continued assessing whether private information had been accessed.
A platform breach became a cryptocurrency test
The attack began on July 15, 2020. Compromised accounts associated with cryptocurrency businesses were used first, followed by accounts belonging to prominent executives, public figures and companies. Fraudulent posts promised to return twice the amount of Bitcoin sent to addresses controlled by the attackers.
Twitter said in its incident summary, reflecting its information as of 8:35 p.m. Pacific time on July 17, that attackers had targeted employees through social engineering and obtained access to internal support tools. The company said 130 accounts were targeted and that attackers initiated password resets, logged in and sent posts from 45 of them. Twitter also said information had been downloaded through its account-data tool for as many as eight non-verified accounts; that count was revised to seven in later findings.
The distinction mattered. There was no evidence on July 17 that Bitcoin’s protocol or cryptography had been breached. The compromised system was Twitter’s centralized account-administration infrastructure. Bitcoin served as the payment rail for the fraud, while its public ledger gave exchanges and investigators a common set of destination addresses to monitor.
Exchanges faced the intervention question
The Department of Financial Services had instructed regulated cryptocurrency companies at 6:59 p.m. on July 15 to block the addresses used by the attackers if they had not already done so. Its July 17 survey examined how firms acted on that warning and what controls they maintained around social-media incidents.
That response highlighted a tension already present in cryptocurrency markets. A Bitcoin transfer confirmed by the network cannot be recalled by an exchange or regulator. A custodial platform can, however, screen a withdrawal before broadcasting it. Blocking a known fraud address may protect customers, but it depends on rapid identification, information sharing and control over funds held inside the intermediary.
On July 17, the regulator had not published comprehensive figures showing how many attempted transfers had been stopped. Claims about the effectiveness of individual companies therefore remained incomplete in the event-day record.
What was known—and what was not
By July 17, Twitter was restoring access to users caught in its emergency restrictions, and the FBI’s San Francisco division was leading a federal inquiry. The identity of the attackers, the full path into Twitter’s systems and the extent of access to private communications were still unresolved. No arrests or charging decisions belonged in the event-day account.
The immediate institutional consequence was nevertheless clear: a social-media compromise had triggered coordinated action by a state financial regulator, federal investigators and cryptocurrency platforms. For exchanges, the episode turned address screening and withdrawal controls from abstract compliance functions into visible defenses against a live, globally distributed fraud.
Later context
New York’s October 14, 2020 investigation report calculated that the attackers stole approximately $118,000 worth of Bitcoin and documented that several regulated companies blocked attempted customer transfers. Federal charging records released later identified three Bitcoin addresses associated with the scheme. Those findings clarify the July 17 record but were not established publicly in full on that date.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

