CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

2020 Twitter account hijacking

July 2020 compromise of multiple verified Twitter accounts to post scam Tweets

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionSep 21, 2026
Entity authorityQ97400200
Source-derived summary

On July 15, 2020, between 20:00 and 22:00 UTC, 130 high-profile Twitter accounts were compromised by outside parties to promote a bitcoin scam. Hackers used social engineering against Twitter employees to gain access to administrative tools, allowing them to post the tweets directly. The scam tweets asked individuals to send bitcoin currency to a specific cryptocurrency wallet, with the promise that money sent would be doubled and returned – within minutes, one account received over 320 deposits with a value of over US$110,000 before the scam messages were removed by Twitter.

CrowdStrike co-founder Dmitri Alperovitch described the incident as "the worst hack of a major social media platform yet", and security researchers highlighted the risks of social media manipulation during large events such as the lead-up into the 2020 United States presidential election. On July 31, 2020, the U.S. Department of Justice announced charges against three individuals in connection with the incident.

Incident

Forensic analysis of the scam showed that the initial scam messages were first posted by accounts with short, one- or two-character distinctive names, such as "@6". This was followed by cryptocurrency Twitter accounts at around 20:00 UTC on July 15, 2020, including those of Coinbase, CoinDesk and Binance. The scam then moved to more high-profile accounts with the first such tweet sent from Elon Musk's Twitter account at 20:17 UTC. Other supposedly compromised accounts included those of well-known individuals such as Barack Obama, Joe Biden, Bill Gates, Jeff Bezos, MrBeast, Michael Bloomberg, Warren Buffett, Floyd Mayweather Jr., Kim Kardashian, and Kanye West; and companies such as Apple, Uber, and Cash App. Twitter believed 130 accounts were affected, though only 45 were actually used to tweet the scam message; most of the accounts that were accessed in the scam had at least a million followers.

The tweets posted by the compromised accounts claimed that the sender, in charity, would repay any user double the value of any bitcoin they sent to given wallets, often as part of a COVID-19 relief effort.

Editorial summary

Begin with the source’s own compact description: “2020 Twitter account hijacking” is july 2020 compromise of multiple verified Twitter accounts to post scam Tweets. The dossier treats that line as a proposition to test through Twitter, account and hijacking, not as a finished interpretation.

Editorial reviewA dependable orientation record for establishing vocabulary, names and a first evidence trail. The current lead gives the account dated anchors—2020—that can be checked directly. The selected authority fields contribute no independent date. For this dossier, Twitter, account and hijacking is the immediate research focus.
Editorial analysis

Why this record matters

The phrase “july 2020 compromise of multiple verified Twitter accounts to post scam Tweets” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.

Evidence profile

Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 21, 2026. The linked authority identifier is Q97400200. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2020.

Critical limits

Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “2020 Twitter account hijacking”, its source revision and the description used here.
  2. Expand the search: follow 2020 Twitter account hijacking primary sources, 2020 Twitter account hijacking archive and Twitter research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “2020 Twitter account hijacking”?
  2. Which cited source is closest to the event, object or claim?
  3. What terminology or title could unlock a more precise catalogue search?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from 2020 Twitter account hijacking” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.