2020 Twitter account hijacking
July 2020 compromise of multiple verified Twitter accounts to post scam Tweets

On July 15, 2020, between 20:00 and 22:00 UTC, 130 high-profile Twitter accounts were compromised by outside parties to promote a bitcoin scam. Hackers used social engineering against Twitter employees to gain access to administrative tools, allowing them to post the tweets directly. The scam tweets asked individuals to send bitcoin currency to a specific cryptocurrency wallet, with the promise that money sent would be doubled and returned – within minutes, one account received over 320 deposits with a value of over US$110,000 before the scam messages were removed by Twitter.
CrowdStrike co-founder Dmitri Alperovitch described the incident as "the worst hack of a major social media platform yet", and security researchers highlighted the risks of social media manipulation during large events such as the lead-up into the 2020 United States presidential election. On July 31, 2020, the U.S. Department of Justice announced charges against three individuals in connection with the incident.
Incident
Forensic analysis of the scam showed that the initial scam messages were first posted by accounts with short, one- or two-character distinctive names, such as "@6". This was followed by cryptocurrency Twitter accounts at around 20:00 UTC on July 15, 2020, including those of Coinbase, CoinDesk and Binance. The scam then moved to more high-profile accounts with the first such tweet sent from Elon Musk's Twitter account at 20:17 UTC. Other supposedly compromised accounts included those of well-known individuals such as Barack Obama, Joe Biden, Bill Gates, Jeff Bezos, MrBeast, Michael Bloomberg, Warren Buffett, Floyd Mayweather Jr., Kim Kardashian, and Kanye West; and companies such as Apple, Uber, and Cash App. Twitter believed 130 accounts were affected, though only 45 were actually used to tweet the scam message; most of the accounts that were accessed in the scam had at least a million followers.
The tweets posted by the compromised accounts claimed that the sender, in charity, would repay any user double the value of any bitcoin they sent to given wallets, often as part of a COVID-19 relief effort.
Begin with the source’s own compact description: “2020 Twitter account hijacking” is july 2020 compromise of multiple verified Twitter accounts to post scam Tweets. The dossier treats that line as a proposition to test through Twitter, account and hijacking, not as a finished interpretation.
Why this record matters
The phrase “july 2020 compromise of multiple verified Twitter accounts to post scam Tweets” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.
Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 21, 2026. The linked authority identifier is Q97400200. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2020.
Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “2020 Twitter account hijacking”, its source revision and the description used here.
- Expand the search: follow 2020 Twitter account hijacking primary sources, 2020 Twitter account hijacking archive and Twitter research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “2020 Twitter account hijacking”?
- Which cited source is closest to the event, object or claim?
- What terminology or title could unlock a more precise catalogue search?
Search terms from this dossier
This entry incorporates text from “2020 Twitter account hijacking” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.