The U.S. Securities and Exchange Commission said on January 9, 2024, that its official @SECGov account on X had been compromised and that a post announcing approval of spot-bitcoin exchange-traded funds was unauthorized.

The false announcement appeared at 4:11 p.m. Eastern, according to the SEC’s subsequent incident chronology. It purported to say the Commission had approved bitcoin ETFs for listing on registered national securities exchanges. At 4:26 p.m., SEC Chair Gary Gensler used his own account to say the regulator’s account had been compromised and that the Commission had not approved the listing and trading of spot-bitcoin exchange-traded products.

A false signal from an authoritative channel

The post arrived at an unusually sensitive moment. Fund sponsors and exchanges were awaiting SEC decisions on proposed products designed to hold bitcoin and issue exchange-traded shares. Because an SEC order was the necessary regulatory step, market participants had strong reason to treat a message from the agency’s authenticated account as significant—at least until an official order or denial appeared on the SEC website.

The compromised account therefore carried more market power than an anonymous rumor. The information was false, but the channel was authentic, collapsing the distinction that traders ordinarily use to separate speculation from an attributable regulatory announcement.

SEC staff told reporters on January 9 that the post was not made by the agency or its staff. The agency also said unauthorized access had occurred for a brief period shortly after 4 p.m. and had been terminated. On the evidence available that evening, the identity of the intruder, the precise access method and the extent of any activity beyond the social-media account remained unresolved.

Bitcoin reversed as the denial spread

Contemporaneous Associated Press reporting described the bitcoin-U.S.-dollar price moving from about $46,730 to just below $48,000 after the unauthorized post, then falling to around $45,200 after the denial. AP reported bitcoin near $46,150 at 6:15 p.m. Eastern.

That sequence covers approximately the period from the 4:11 p.m. post through 6:15 p.m. It shows the direction and approximate scale of the reaction, but it is not a complete market benchmark: the report did not identify a particular exchange, consolidated index, quote convention or sampling method. Bitcoin trades continuously across venues, so prices and timing could differ elsewhere. No percentage return or liquidation total is inferred from those observations.

The reversal mattered beyond its duration. It demonstrated that bitcoin’s globally fragmented spot market could respond within minutes to an apparent decision by a U.S. securities regulator, before participants had verified the corresponding legal record. Traders who acted on the authenticated post faced both information risk and execution risk as the correction propagated.

A communications-security failure

X’s preliminary investigation, reported on January 9, said an unidentified person had obtained control of a phone number associated with @SECGov through a third party. X also said two-factor authentication was not enabled on the account. Those were contemporaneous platform findings, not yet a complete forensic account.

The episode raised an institutional question separate from the ETF decision: how should markets authenticate government action when an official distribution channel is compromised? An agency social-media account could amplify information instantly, but it was not itself the legal instrument approving an exchange rule change. The authoritative record remained an order posted through the SEC’s formal publication process.

Later context

On January 10, 2024, the SEC issued the actual order approving 11 proposed exchange-rule changes for spot-bitcoin products. On January 12, the agency published a fuller chronology, and on January 22 it said the compromise involved an apparent SIM-swap attack after multifactor authentication had remained disabled since July 2023. Those later findings clarify the breach but do not change what was established on January 9: the approval post was unauthorized, the account was compromised and no approval had been issued when the false message appeared.

Primary sourceSEC — SECGov X Account incident statements and chronology

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.