The U.S. Justice Department announced charges on July 31, 2020, against three people accused of participating in the breach that turned prominent Twitter accounts into distribution channels for a bitcoin-doubling scam.
The announcement converted one of the month’s most visible cryptocurrency frauds from an unresolved platform-security crisis into a criminal case spanning the United States and United Kingdom. It also showed why Bitcoin’s public transaction ledger could become investigative evidence even when participants operated through aliases and online accounts.
Mason Sheppard, 19, of Bognor Regis, United Kingdom, was charged in the Northern District of California with conspiracy to commit wire fraud, conspiracy to commit money laundering and intentionally accessing a protected computer. Nima Fazeli, 22, of Orlando, Florida, was charged with aiding and abetting intentional access to a protected computer. The Justice Department said a third defendant was a juvenile whose matter had been referred to the state attorney in Florida’s 13th Judicial Circuit.
Those were allegations contained in criminal complaints, not findings of guilt. All defendants remained entitled to the presumption of innocence.
A platform breach became a bitcoin fraud case
The July 15, 2020 attack reached accounts associated with public figures and companies, including Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and Uber. Cryptocurrency businesses were also caught in the breach. The federal complaints identified compromised accounts associated with Coinbase, Gemini, Binance, Bitfinex and other industry participants.
Fraudulent posts directed users to send bitcoin on the false promise that twice the amount would be returned. According to the complaints, the attackers obtained access through a combination of social engineering and Twitter’s internal account-management systems.
Twitter’s July 30 incident update said attackers used employee credentials to target 130 accounts. They ultimately posted from 45 accounts, accessed the direct-message inboxes of 36 and downloaded account data from seven. Twitter described the entry method as phone spear phishing directed at a small number of employees. The company said the attackers first gained information about internal processes and then targeted employees who could reach account-support tools.
That account placed the security failure inside Twitter’s operational controls rather than in Bitcoin itself. Bitcoin was the payment mechanism selected for the fraud, while the distribution advantage came from unauthorized control of trusted social-media identities.
What investigators said the ledger showed
An affidavit supporting the federal complaints described a defined blockchain-analysis window running from July 15 through July 16, 2020. Investigators counted approximately 415 incoming transfers to the primary scam address, totaling about 12.86 BTC. They valued that amount at $117,457.58 using a stated reference rate of $9,133.56 per bitcoin as of July 16.
The affidavit also counted 11 outgoing transfers totaling approximately 12.83 BTC, or 99.74% of the bitcoin deposited at that address. These figures were law-enforcement assertions drawn from one identified address and a specified period; they were not a complete accounting of every address, victim loss or subsequent movement connected to the incident.
The Justice Department said IRS Criminal Investigation personnel analyzed the blockchain and de-anonymized bitcoin transactions in a way that contributed to identifying two alleged participants. That claim mattered institutionally: the visible ledger did not automatically reveal a person’s identity, but investigators asserted that transaction analysis combined with exchange, communications and account records could connect pseudonymous activity to individuals.
The significance on July 31
The case demonstrated two distinct dependencies surrounding cryptocurrency fraud. Attackers could exploit trust created outside a blockchain—in this instance, verified social-media accounts—to induce irreversible transfers. Investigators could then use the blockchain’s permanent transaction history as one part of a broader evidentiary trail.
The July 31 charges did not establish who performed every stage of the breach, prove the complaints’ allegations or resolve Twitter’s internal-security failures. They did establish that the bitcoin scam had produced coordinated federal, state and international enforcement action only sixteen days after the attack.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

