Twitter suffered a coordinated security breach on July 15, 2020, in which attackers took control of prominent accounts and used them to solicit bitcoin through fraudulent promises to return twice the amount sent. Accounts associated with cryptocurrency companies appeared early in the campaign before the same scheme spread through accounts belonging to political figures, technology executives and major corporations.
Twitter acknowledged on July 15 that people had successfully targeted employees with access to internal systems and tools. The company temporarily restricted posting and password-reset functions for many accounts while it tried to contain the intrusion. That response made the episode more than a collection of stolen passwords: the available evidence pointed to misuse of Twitter’s own account-management infrastructure.
What the event-day record established
Contemporaneous Reuters reporting identified affected accounts belonging to Joe Biden, Barack Obama, Elon Musk, Bill Gates, Jeff Bezos, Apple and Uber, among others. Cryptocurrency-related accounts were also hijacked, including accounts associated with Coinbase, Gemini and Binance. The fraudulent messages directed readers to send bitcoin to specified addresses on the false promise that a larger amount would be returned.
Reuters updated its report at 11:31 p.m. Eastern time on July 15 and said publicly available blockchain records showed the apparent scammers had received more than $100,000 in cryptocurrency. That was an event-day estimate, not a final loss calculation. The report did not specify its complete address set, bitcoin total, exchange-rate source or valuation timestamp, so the dollar amount should be read as a contemporaneous threshold rather than an audited total.
Twitter also prevented at least some verified accounts from publishing for several hours. That unusually broad restriction demonstrated the operational severity of the incident, although the full number of targeted and successfully commandeered accounts was not yet established publicly on July 15.
Why the breach mattered for crypto
The incident was not evidence that Bitcoin’s protocol had been compromised. The blockchain continued processing transactions according to its rules; the attackers instead exploited trust in authenticated social-media identities and Bitcoin’s irreversible settlement model.
That distinction mattered because exchanges, wallet providers, public officials and technology leaders used Twitter as a real-time communications channel. A message arriving from an authentic, verified account could appear materially more credible than an imitation account. Once bitcoin was transferred, neither Twitter nor a recipient institution could reverse the underlying blockchain transaction by editing or deleting the fraudulent post.
The attack therefore exposed a security boundary outside Bitcoin itself: control over the communications systems through which payment instructions and investment claims were distributed. It also showed why cryptocurrency businesses needed rapid address-blocking and incident-response procedures even when their trading or custody systems had not been breached.
Confirmations published after July 15
Twitter’s July 18 incident update, summarizing information available as of July 17 at 8:35 p.m. Pacific time, said 130 accounts were targeted. Attackers initiated password resets, logged in and sent posts from 45 of them. Twitter attributed the access to social engineering directed at a small number of employees and said internal support tools were used.
A federal complaint released on July 31 supplied a narrower blockchain measurement for the primary scam address. Investigators counted approximately 415 incoming transfers totaling 12.86 BTC between July 15 and July 16. They valued that amount at $117,457.58 using a stated July 16 rate of $9,133.56 per bitcoin. Those figures are later investigative context, not information Coinburn treats as finalized on July 15; they cover the identified primary address and the complaint’s defined measurement window.
An October 2020 New York Department of Financial Services report further documented the response by regulated cryptocurrency companies. Those later findings clarify the breach’s scale without changing what was known while Twitter was still containing it on July 15.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

