{"id":25071,"date":"2026-04-04T12:06:18","date_gmt":"2026-04-04T12:06:18","guid":{"rendered":"https:\/\/bitunikey.com\/news\/x-platform-to-auto-lock-accounts-on-first-crypto-mention-to-kill-phishing-scams\/"},"modified":"2026-04-04T12:06:23","modified_gmt":"2026-04-04T12:06:23","slug":"x-platform-to-auto-lock-accounts-on-first-crypto-mention-to-kill-phishing-scams","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/x-platform-to-auto-lock-accounts-on-first-crypto-mention-to-kill-phishing-scams\/","title":{"rendered":"X Platform to Auto-Lock Accounts on First Crypto Mention to Kill Phishing Scams"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Elon Musk\u2019s X is rolling out a security feature that will automatically lock any account that mentions cryptocurrency for the first time \u2014 requiring additional verification before posting resumes \u2014 a direct response to a wave of account hijacking campaigns exploiting social trust to promote scam tokens.<\/p>\n<div id=\"cn-block-summary-block_d59c29e1d29b145132be213b0b020f48\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>X Head of Product Nikita Bier confirmed the auto-lock feature, saying it targets the financial incentive behind crypto phishing attacks on the platform<\/li>\n<li>The measure follows a surge in account hijacking incidents, including the April 1 compromise of Predictfully founder Benjamin White\u2019s account, which was used to push scam content and extort $4,000 from the real owner<\/li>\n<li>Bier estimates the feature should eliminate 99% of the incentive behind current phishing operations and called out Google for failing to block phishing emails at the Gmail level<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The auto-lock triggers on an account\u2019s first-ever cryptocurrency-related post. Once triggered, the account is locked, and the user must complete verification before regaining access. Bier described it as targeting the core attack vector: hackers gain account access through phishing emails, lock out the original owner, and use the account\u2019s established follower trust to promote fraudulent tokens, fake giveaways, and memecoins.<\/p>\n<h1 class=\"wp-block-heading\">The Feature<\/h1>\n<p>\u201cThis should kill 99% of the incentive,\u201d Bier wrote in response to a user\u2019s account of how they lost control of their profile to a phishing attack disguised as a copyright violation notice. The attacker had used a pixel-perfect fake login page to harvest the user\u2019s credentials and two-factor authentication codes before locking them out and beginning scam promotion.<\/p>\n<h2 class=\"wp-block-heading\">What This Targets<\/h2>\n<p>Crypto-linked account hijacking on X has been a documented and persistent problem since the platform\u2019s days as Twitter. The auto-lock builds on earlier platform efforts to eliminate mention-spam campaigns and coordinated account behavior used in crypto promotions. Long-term users who have never posted about cryptocurrency will face verification on their first such post, while legitimate accounts, Bier indicated, can regain access quickly through the process.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>Bier also publicly criticized Google for allowing phishing emails to reach users through Gmail. \u201cGoogle isn\u2019t doing shit to stop the phishing,\u201d he wrote \u2014 framing the auto-lock as a platform-level workaround to a vulnerability upstream that X cannot directly control.<\/p>\n<p>The U.S. Federal Trade Commission has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ftc.gov\/news-events\/data-visualizations\/data-spotlight\/2022\/06\/reports-show-scammers-cashing-crypto-craze\" target=\"_blank\" rel=\"nofollow\">documented <\/a>how social media crypto scams have surged into a multi-billion dollar problem, with victims often unable to recover funds given the irreversibility of on-chain transfers. This structural reality is what makes hijacked accounts with established follower trust so valuable to attackers \u2014 and what the auto-lock directly targets by severing the link between account access and immediate monetization via crypto promotion.<\/p>\n<h2 class=\"wp-block-heading\">Limitations<\/h2>\n<p>Critics have flagged that the measure only intervenes after an account has already been compromised via phishing. If email providers do not better filter phishing emails upstream, the attack chain remains intact. The feature could also create friction for legitimate first-time crypto posts from established accounts, though Bier indicated the verification process will be brief for genuine users.<\/p>\n<p>As broader crypto hack and phishing losses have shown improvement in recent months \u2014 with February 2026 recording the lowest monthly total since March 2025 \u2014 the $285 million Drift Protocol exploit this week is a sharp reminder that headline risk remains high. X\u2019s new feature addresses one specific and high-volume attack vector within a much larger ecosystem of crypto-linked fraud.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Elon Musk\u2019s X is rolling out a security feature that will automatically lock any account that mentions cryptocurrency for the first time \u2014 requiring additional verification before posting resumes \u2014&hellip;<\/p>\n","protected":false},"author":1,"featured_media":25072,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-25071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/25071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=25071"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/25071\/revisions"}],"predecessor-version":[{"id":25073,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/25071\/revisions\/25073"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/25072"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=25071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=25071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=25071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}