Twitter’s first detailed disclosure of the July 15 security breach established the scale of a bitcoin scam that had commandeered some of the platform’s most trusted voices. The company’s July 18 post, which framed the record available for July 19, said attackers targeted 130 accounts and successfully reset passwords, logged in and sent posts from 45. That made the central fact larger than a handful of celebrity takeovers: access to Twitter’s internal support systems had become the distribution channel for a digital-asset fraud.

The company said its summary reflected findings through July 17 at 8:35 p.m. Pacific time and remained subject to change. Its account was still preliminary. Twitter attributed the entry point to manipulation of a small number of employees, whose credentials let the attackers pass two-factor protections and reach internal tools. It did not identify the perpetrators, publish a complete account list or provide a finished technical reconstruction.

A platform breach, monetized in bitcoin

The fraudulent posts promised to return twice the bitcoin sent to addresses controlled by the attackers. Accounts associated with Elon Musk, Barack Obama, Apple and Uber were among those cited in contemporaneous blockchain-analysis reporting. The attack initially touched cryptocurrency-facing accounts before spreading to figures and companies with much broader audiences, turning account credibility into the scam’s main asset.

Elliptic’s July 16 tracing report counted just over 400 payments to the bitcoin addresses promoted through compromised accounts, with a gross value of about $121,000. That figure covered receipts observed at the identified addresses, not a court-tested tally of victim losses. It also depended on Elliptic’s address attribution and dollar conversion at the time of analysis. The firm reported that almost all funds had already moved to 12 new addresses and that a small portion had reached known regulated exchanges.

The contrast mattered. The attackers exploited centralized control over a communications platform, but the settlement trail was visible on Bitcoin’s public ledger. Public visibility did not identify a person by itself: addresses are pseudonymous, ownership can be uncertain, and transactions can be split or routed through additional wallets. It did, however, give exchanges and investigators a common set of transactions to monitor. Elliptic said it had added the associated bitcoin and XRP addresses to its screening data; it reported no XRP receipts as of its July 16 analysis.

Trust was the scarce resource

The July 19 significance was institutional rather than price-driven. Twitter temporarily restricted posting and password changes for many accounts while it contained the incident. Its disclosure said the attackers could see email addresses and phone numbers exposed through some internal support tools. For up to eight affected accounts, all described as unverified, the attackers downloaded account information using the “Your Twitter Data” function. The company was still reviewing whether taken-over accounts exposed additional information.

For cryptocurrency businesses, the episode showed that operational security extended beyond wallets, exchanges and private keys. A compromised communications channel could manufacture apparently authentic instructions from a known company or public figure. The fraud did not alter Bitcoin’s transaction rules or compromise its ledger; it abused confidence in identity and messaging, then used bitcoin as the payment rail.

What remained unknown on July 19

Twitter said it was working with law enforcement and continuing forensic review, but the July 19 record did not establish who organized the intrusion, the complete path through Twitter’s systems, the final number of people who lost money or the ultimate destination of the bitcoin. The reported payment total was a contemporaneous analytics estimate rather than a final legal finding. Those uncertainties were material: the company’s disclosure was an incident update, while wallet-clustering conclusions remained analytical judgments. The verified development was narrower but consequential—Twitter had confirmed that attackers reached internal support tools, targeted 130 accounts and used 45 of them to publish after logging in.

Primary sourceTwitter — An update on our security incident

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.