@0xSunNFT Over these past couple of days on Twitter, I really got lured into a phishing/soc-engineering scheme—my account almost couldn’t be saved.

On August 25, I received a phishing email disguised as a DMCA infringement warning. I accidentally clicked and ended up on their phishing site. The next day, both my computer and phone logins were kicked out. When I tried to log in again, it first told me to change the password; when I changed it, I was blocked again saying the request count was too high and to try later. I submitted an appeal, and then tried again after 12 hours and 24 hours—still got the exact same message.

A few more hours later, I received an email from X official saying that the contact email doesn’t match the email bound to the account. That’s when I realized the hacker had already used the old login session to change the account details. For a while I thought the account was gone for good, but in the end I got it back with help from a friend.

Once someone takes over your account, the $BTC assets attached on-chain are exposed too.