The message says someone just signed in to your account from a device you do not recognize, and asks you to confirm it was you. It is the kind of alert real platforms genuinely send, which is exactly why it works as bait. The Guardian reported this week on a wave of these messages aimed at X users, sent to take over accounts and run cryptocurrency phishing through them.
The mechanics are worth understanding, because the defense is not the one most people reach for.
Why the alert format is the attack
A security warning is engineered to create urgency, and a fake one inherits that for free. The message tells you something bad may already be happening, offers a single obvious remedy, and gives you a reason to act before thinking. Click the link and you land on a sign-in page that looks like the real one. Enter your details and you have handed them over directly. In many cases the attacker then changes the password and recovery email, and the account is gone.
The reason to want your account is reach. An unfamiliar account promoting a token gets ignored; the same pitch from an account your followers already know does not. The US Federal Trade Commission warns that scammers impersonate well-known companies and post links to fake giveaways and airdrops designed to drain a victim's wallet. A hijacked account with a real following is the delivery mechanism.
The losses behind this are not marginal. In its 2025 annual report, the FBI's Internet Crime Complaint Center recorded 181,565 cryptocurrency-related complaints totaling more than $11 billion, a 22% rise on 2024. Crypto-related cases carried an average loss of $62,604, against $20,699 across all complaint types. Total reported cybercrime losses passed $20 billion across 1,008,597 complaints.
The check that always works
Do not evaluate the message. Evaluate the account.
Whatever a message claims, open the app or type the site's address into your browser yourself and look at your account's security settings. A genuine new-device login will be visible there. A fabricated one will not. This works regardless of how convincing the message is, how right the sender address looks, or how good the fake page is, because it never touches the attacker's infrastructure at all.
That matters because the usual advice to inspect the sender address is weaker than it sounds. Display names are trivially spoofed, lookalike domains substitute characters that are hard to spot, and a link's visible text need not match its destination. Treating a legitimate-looking sender as reassurance is precisely the judgment the attack is designed to exploit.
What actually hardens the account
Turn on two-factor authentication, and pick the right kind. Not all second factors are equal against this attack. A hardware security key is strongest, because it verifies the site's real address before it releases anything, so it simply will not authenticate to a copycat page. An authenticator app is the next best option. SMS codes are the weakest, both because texts can be intercepted through SIM-swap attacks and because a code you read off your phone can be typed straight into a fake page by an attacker relaying it in real time.
Never enter credentials from a link. Navigate to the site yourself, every time, without exceptions for messages that look official.
Use a unique password. The UK's National Cyber Security Centre suggests three random words as a practical way to get length without making it unmemorable. The point of uniqueness is containment: reused credentials turn one compromised account into a set of them, and attackers try stolen pairs against email and financial services automatically.
Review connected apps periodically. Third-party applications you authorized years ago may retain posting access. Revoke anything you no longer use.
If you have already entered your details
Move in order. Change the password on the affected account first, then on any other account sharing that password. Turn on two-factor authentication if it was off. Check the account's active sessions and sign out everything you do not recognize, which evicts an attacker holding a live session. Review authorized apps and recovery details, since changing a password does not remove access an attacker has already granted themselves elsewhere.
In the United States, report it to the FTC and to the FBI's Internet Crime Complaint Center. Reporting will not usually recover money, but IC3 complaints are what make the aggregate figures above visible, and speed occasionally matters where funds have not yet moved.



