Crypto scammers piggybacking Trump’s twitter, cloning Medium, stealing crypto

Joe Gaebel
2 min readOct 14, 2020

Getting this out quickly:

  1. Go to Trump’s twitter feed (sorry)
  2. Click a post, and look at the replies
  3. Find something similar to the following:

The youtube video is simply a link to a Cybertruck commercial. But the link in the image is a fairly nicely designed website impersonating Elon Musk’s Medium page.

The fake medium has one article, encouraging people to send crypto and receive double back as a marketing ploy. It then links off to sub pages for further instruction.

Surprisingly good design, and links that point back to Medium

Further, Crypto Rand, Aleksandar Svetski, Liz Klinger, Nate Ruben, you’re being impersonated at this medium clone.

A quick WHOIS reveals the following:

I’ve reached out to the abuse email, explaining the above.

Going back to the Twitter user in question, https://twitter.com/iosuaopeta55

Looks like he used to be named Iosua Opeta, some NFL guy.

The obvious attack vector here is finding a previously verified Twitter account, and changing the name. That little blue ribbon emoji looks a lot like a guarantee about the user’s name, doesn’t it.

I’ve reported to twitter that poor Iosua has been hacked.

Stay safe out there.

--

--