Press Enter to search · ESC to close

Crypto

Nano Labs Founder Jack Kong Regains X Account After AI-Assisted Phishing Attack

Nano Labs founder Jack Kong has recovered his X account after attackers used a phishing email and an AI misclassification to steal his verification code. The breach highlights how crypto executives remain prime targets and how AI security tools can themselves become vulnerabilities.

Nano Labs Founder Recovers Hijacked X Account After Sophisticated Phishing Attack

Jack Kong, founder of Nasdaq-listed BNB treasury company Nano Labs, has regained control of his X (formerly Twitter) account following a targeted phishing attack that exploited both his personal email and an AI-powered verification tool. The attackers briefly used the compromised account to publish fraudulent content before access was restored on September 28.

How the Attack Unfolded

The breach did not rely on brute force or platform vulnerabilities. Instead, it combined social engineering with a dangerous over-reliance on automated systems. The attacker sent a phishing email to Kong’s frequently used public inbox. An AI system — likely an email security or link-scanning tool — misclassified the malicious link as an official X third-party verification page. Trusting that automated judgment, Kong entered the verification code X sent to his bound email address into the counterfeit page, handing the attackers full access to his account.

This is a textbook example of what security researchers call “AI-assisted social engineering.” The attacker does not need to defeat a human’s skepticism if they can first defeat the machine that is supposed to protect the human. Once the AI gatekeeper is fooled, the victim’s own trust in their tools becomes the vulnerability.

Why Crypto Founders Are Prime Targets

Kong is far from an isolated case. Crypto executives, founders, and prominent traders are among the highest-value targets on X because their accounts carry implicit endorsement power. A single fraudulent post from a trusted founder’s handle can trigger a wave of wallet-draining scams, fake token launches, or phishing links that reach hundreds of thousands of followers within minutes.

  • Reputation as an attack surface: In crypto, credibility is capital. Hijacked accounts weaponize that credibility instantly.
  • Speed of exploitation: Scam posts often stay live for only minutes but can still capture significant funds before deletion.
  • Regulatory blind spots: Social media platforms offer limited recourse, and recovery timelines are unpredictable.

Nano Labs, which positions itself as a BNB-focused crypto treasury company listed on U.S. equity markets, sits at the intersection of traditional finance and digital assets — a profile that makes its leadership especially attractive to attackers seeking both financial and reputational leverage.

Industry Implications and Forward Look

The incident underscores a broader truth: as AI tools become embedded in email filtering, link scanning, and account security, attackers will increasingly design campaigns specifically to fool those tools. The next frontier of account security is not just stronger passwords or hardware keys, but adversarial testing of the AI layers that sit between users and threats.

For crypto firms, the lesson is clear. Executive social media accounts should be treated as critical infrastructure, subject to the same hardening as corporate wallets: hardware security keys, dedicated non-public email addresses, and mandatory human verification for any link requesting credentials. Until platforms and security vendors close the gap between AI convenience and AI fallibility, high-profile founders will remain the softest entry point into the industry’s trust networks.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback