SEC Admits MFA Deactivation Led to X Account Hack

SEC confirms disabling MFA led to its X account hack on Jan 9, triggering false Bitcoin ETF approval news and impacting the crypto market.
US SEC Rescinds Crypto Accounting Rule SAB 121 After Gensler's Exit

The U.S. Securities and Exchange Commission (SEC) has confirmed a breach of its official X account (formerly Twitter), attributing the incident to a SIM swap attack. This security lapse occurred on January 9 when an unauthorized entity gained control of the @SECGov handle, erroneously announcing the SEC’s approval of the first-ever spot bitcoin exchange-traded funds.

Advertisement
Advertisement

Impact on Cryptocurrency Market

Following the false tweet, the cryptocurrency market witnessed immediate fluctuations. Bitcoin’s value soared to approximately $48,000 before plummeting below $46,000 once the SEC refuted the approval of the Bitcoin ETF. 

Investigations revealed that the breach was facilitated by a SIM swap, wherein the victim’s phone number was illicitly transferred to another device. This enabled the perpetrator to intercept SMS messages and calls, ultimately resetting the account’s password. Compounding the issue was the absence of two-factor authentication (MFA) on the SEC’s account, a critical security feature that had been disabled since July 2023 due to access difficulties.

Advertisement
Advertisement

Reactions and Responses

Elon Musk, X’s owner and a long-time critic of the SEC, responded to the incident with mockery. In contrast, X denied any system breach on their part. Meanwhile, the SEC confirmed the lack of evidence pointing to any compromise of their other systems, data, or devices. The breach was isolated to the telecom carrier, sparking a comprehensive investigation involving multiple law enforcement and federal agencies.

Advertisement
Advertisement

SEC’s Security Measures

Post-incident, the SEC has reactivated MFA for all its social media accounts. This move reflects a heightened awareness of digital security risks and the necessity of robust protective measures in safeguarding sensitive information, particularly for influential government agencies.

Moreover, multiple law enforcement and federal agencies, including the FBI and Department of Homeland Security, are investigating the breach. They aim to uncover how the attacker persuaded the telecom carrier to execute the SIM swap and how they knew the specific phone number linked to the SEC’s account.

Read Also: Grayscale Facing Intense Backlash for Market Meltdown, Here’s Why

Advertisement
Kelvin Munene Murithi
Kelvin Munene is a crypto and finance journalist with over 5 years of experience, offering in-depth market analysis and expert commentary . With a Bachelor's degree in Journalism and Actuarial Science from Mount Kenya University, Kelvin is known for his meticulous research and strong writing skills, particularly in cryptocurrency, blockchain, and financial markets. His work has been featured across top industry publications such as Coingape, Cryptobasic, MetaNews, Cryptotimes, Coinedition, TheCoinrepublic, Cryptotale, and Analytics Insight among others, where he consistently provides timely updates and insightful content. Kelvin’s focus lies in uncovering emerging trends in the crypto space, delivering factual and data-driven analyses that help readers make informed decisions. His expertise extends across market cycles, technological innovations, and regulatory shifts that shape the crypto landscape. Beyond his professional achievements, Kelvin has a passion for chess, traveling, and exploring new adventures.
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.