Cryptocurrency
Following Funds From The Twitter Hack & Bitcoin Scam – Affecting Joe Biden, Elon Musk, And Others
Forbes reports, “A massive hack affected Twitter around 3pm EDT Wednesday (July 15th 2020), in which many high-profile accounts were used to tweet out a large-scale doubling scam. “It is unclear exactly how the hackers gained access to make the tweets from these accounts, but Twitter posted an update which corroborated reports that indicated company personnel and internal admin tools were involved. “Considering that the hackers […]
Forbes reports, “A massive hack affected Twitter around 3pm EDT Wednesday (July 15th 2020), in which many high-profile accounts were used to tweet out a large-scale doubling scam.
“It is unclear exactly how the hackers gained access to make the tweets from these accounts, but Twitter posted an update which corroborated reports that indicated company personnel and internal admin tools were involved.
“Considering that the hackers had control over some of the most influential accounts on Twitter, posting a simple Bitcoin scam and exposing their access is a curious choice. As Kris Holt said, It could have been a lot worse – Accounts were frozen quickly, and the main known hacker address only received around $120,000 worth of BTC at the time of writing. Tracking these funds, however small the amount, is important and the FBI is reportedly investigating:
“Bitcoin is a public blockchain, so anyone can pull and investigate all of the hack-associated transactions and addresses from their own node. Zach Finzi and I use this publicly available blockchain data to model the funds received and subsequently sent by the scammer(s).

Bitcoin Network Topology Visualization Twitter Hack/Cryptoforhealth Scam
SCREENSHOT – NTERMINAL DATA IN SPLUNK
“The above graph uses the 3d Network Topology App for Splunk SPLK +0.5%’s Machine Learning Tool Kit. It shows the indexed transactions between addresses implicated in the scam. Each node represents an individual address and the edges represent a set of transactions and transfers of BTC between the two nodes. Blue nodes are those linked to the Twitter hack, and blue edges represent transactions between them. Green edges represent funds received by the hacker(s), and orange ones show where they sent their funds.
“To better visualize the movement of funds we can use a Sankey diagram:

Sankey Diagram of BTC transactions associated with the Twitter Hack
SCREENSHOT – NTERMINAL DATA IN SPLUNK
“In the above image, transaction directionality can better be seen (BTC moves from addresses on the left to those on the right). To reduce complexity, not all transactions or addresses are pictured.
“Here, we can see that the scammer(s) consolidates funds received by apparent victims, before dispersing them to others. Visualizations like these, in addition to various algorithms, are often used in blockchain forensics to help analysts link address ownership/affiliation.
“By aggregating the addresses controlled by the scammer(s) to a single representative wallet, and further limiting the number of transactions displayed (for better viewing), we can see that the addresses which directly received payments have been mostly emptied to a number of other addresses.
“The primary address which the scammer collected payments with, and was linked on the ‘cryptoforhealth’ website, before it was pulled down, can be tracked by anyone here…”
