Fraudsters Send DMS to Users
- The New York Post's X account appears to have been compromised, potentially exposing cryptocurrency users to a scam.
- Several X users within the crypto community have reported receiving private messages from the New York Post's official X account inviting them to participate in a podcast and...
- Alex Katz, founder and CEO of Kerberus, first brought the suspicious messages to light on May 3, sharing a screenshot showing a request sent to author and journalist...
New York Post’s X Account targeted in Crypto Scam
The New York Post’s X account appears to have been compromised, potentially exposing cryptocurrency users to a scam.
Several X users within the crypto community have reported receiving private messages from the New York Post’s official X account inviting them to participate in a podcast and directing them to contact a Telegram account.The messages are suspected to be fraudulent.
Alex Katz, founder and CEO of Kerberus, first brought the suspicious messages to light on May 3, sharing a screenshot showing a request sent to author and journalist Paul Sperry via the official NYPost account.
Drew, a cybersecurity engineer and NFT collector, noted the unusual nature of the attack. ”The interesting thing is that the fraudster has gained unauthorized access, but did not publish a pump.fun address or a wallet drainer. Instead,send the users a message and then forward them to Telegram,” Drew said.
Drew added that the perpetrator blocked replies from users, seemingly to prevent the actual New York Post team from discovering the compromise.
donny Clutterbuck, from the NFT-Bitcoin platform FOMOJIS, also reported being contacted by the hacker, suggesting a possible zoom exploit. Clutterbuck said that clicking to activate sound prompted a pop-up window with options to cancel or activate WiFi, adding, “I suspect that WiFi gives the fraudster access to the network.”
Blockchain investigator ZachxBT noted similarities between this incident and a previous attack where direct messages were sent from The defiant’s X account.

As of yet, there has been no statement regarding the alleged compromise on either the New York Post’s X feed or from Sperry.
Zoom Emerges as a Platform for Crypto Fraud
Fraudsters are increasingly employing social engineering tactics, targeting users directly after establishing initial contact. The video conferencing platform Zoom has recently become a breeding ground for crypto-related scams.
In April,Jake Gallen,CEO of Emblem Vault,cautioned users about malicious actors exploiting zoom after losing $100,000 in cryptocurrency. Gallen was contacted via X about a Zoom interview, during which malware was installed, leading to the emptying of his wallet.
This is not the first time the New York Post’s X account has been compromised. In 2022,an employee’s account was hacked,resulting in the posting of offensive messages disguised as legitimate headlines.
New York Post’s X Account Targeted in Crypto Scam: Your Questions Answered
What happened with the New York Post’s X (formerly Twitter) account?
The New York Post’s official X account was reportedly compromised, and it appears to have been used in a crypto scam. Users within the crypto community reported receiving suspicious direct messages (DMs) from the account.
What kind of messages were sent out?
The fraudulent messages invited users to participate in a podcast and directed them to contact a Telegram account. These messages are believed to be part of a scam.
Who first brought attention to the suspicious activity?
Alex Katz, founder and CEO of Kerberus, brought the issue to light on May 3 by sharing a screenshot of a suspicious message sent from the New York Post’s account. The message was directed to author and journalist Paul sperry.
What makes this scam unusual?
Drew, a cybersecurity engineer and NFT collector, pointed out an interesting aspect of this attack. The perpetrator gained unauthorized access but did not promptly deploy a typical crypto scam technique, like using a “pump.fun” address to promote a token or a wallet drainer. Instead, they used DMs to direct users to Telegram, likely for further exploitation.
What’s the purpose of directing users to Telegram?
Directing users to Telegram likely allowed the scammers to engage in more elegant social engineering tactics, like phishing or attempting to trick users into sending cryptocurrency or revealing their wallet information.
were replies to the messages blocked?
Yes, the perpetrator appears to have blocked replies from users, likely to prevent the real New York Post team from discovering the compromise and taking action.
What about a potential Zoom exploit?
Donny Clutterbuck, from the NFT-Bitcoin platform FOMOJIS, reported being contacted by the hacker and suggested a possible Zoom exploit. According to Clutterbuck, clicking to activate sound prompted a pop-up window asking to cancel or activate WiFi.
Has the New York Post or paul Sperry made a statement?
As of the provided information, there has been no official statement from either the New York Post’s X feed or Paul Sperry regarding the alleged compromise.
Is this the first time the New York Post’s X account has been compromised?
No. The article mentions that in 2022, an employee’s account was hacked, resulting in the posting of offensive messages disguised as legitimate headlines.
How is Zoom being used in crypto scams?
Zoom has become a platform for social engineering in crypto scams. Criminals are targeting users directly, often setting up fake interviews or meetings to gain their trust and install malware.
Can you give an example of a Zoom-related crypto scam?
Yes. Jake Gallen, CEO of emblem Vault, lost $100,000 in cryptocurrency after being contacted via X about a Zoom interview. Malware was installed during the interview,leading to the theft of his funds.
What are some common tactics used in these types of scams?
Fraudsters commonly employ social engineering tactics, targeting users with direct messages and using platforms like Zoom to establish contact and build trust. They may then attempt to install malware or trick victims into revealing sensitive information.
How can cryptocurrency users protect themselves from scams?
Protecting yourself requires a multi-layered approach. Here are some key steps:
- Be cautious of unsolicited messages: Always be wary of direct messages, even if they appear to come from a trusted source.
- verify the source: Before clicking links or following instructions, independently verify the legitimacy of the sender.
- Research before interacting: Do your research on any opportunity or platform before engaging, especially if it involves sharing personal information or sending cryptocurrency.
- Use strong passwords and enable two-factor authentication (2FA): Secure your accounts.
- Beware of Zoom meeting links: Exercise extreme caution with Zoom links, especially those from unknown sources. Malware can be installed during a meeting.
What are the red flags to watch out for?
Keep an eye out for these red flags:
- Unsolicited messages offering investment opportunities or requesting personal information.
- Pressure to act quickly, such as time-sensitive offers.
- requests to send cryptocurrency or provide wallet details.
- Grammatical errors or unusual language in communications.
- Suspicious links or downloads.
Are there any similarities to previous attacks?
Blockchain investigator ZachxBT noted similarities between this incident and a prior attack where direct messages were sent from The Defiant’s X account. This underlines the importance of understanding these common attack patterns to improve security.
What are the key takeaways from the New york Post’s X compromise?
The New York post’s X account compromise is a stark reminder of the risks of crypto scams and social engineering tactics:
- Be vigilant: Always be suspicious of DMs.
- Verify information: Double-check the source of all information.
- Stay informed: Keep up-to-date on the latest scam methods.
| Platform | Vulnerability | Attack Vector | Protection Measures |
|---|---|---|---|
| X (Twitter) | Account compromise | Phishing, social engineering, malware | Verify source, use strong passwords, enable 2FA, scrutinize links, report suspicious activity. |
| Zoom | Malware installation | Fake interviews, malicious links | verify meeting hosts, be wary of file downloads, update software, and avoid sharing sensitive information. |
| telegram | Social engineering, phishing | Impersonation, malicious bots | Never share private keys, be careful about direct messages from unknown users, report suspicious activity immediatly. |
