Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Creator Economy

OpenAI’s X Newsroom Account Was Hijacked—the Fake Token Was the Bait

|Updated: |Author: QUASA Editorial Team|6 min read| 2213
OpenAI’s X Newsroom Account Was Hijacked—the Fake Token Was the Bait

On September 23, 2024, OpenAI’s official Newsroom account on X was compromised and used to promote a nonexistent cryptocurrency called $OPENAI; TechCrunch’s same-day account documented a link to the lookalike domain token-openai.com and a prompt asking visitors to connect a cryptocurrency wallet. The posts have since disappeared, so this is a historical account takeover rather than a current OpenAI token launch.

The central fact remains unchanged: an authentic corporate channel carried an unauthorized financial offer. What has changed is the protection available for some OpenAI product accounts: on April 30, 2026, OpenAI introduced Advanced Account Security for ChatGPT logins, with protection extending to Codex. That newer option is relevant to creators protecting sensitive work, but it neither explains nor retroactively secures the separate Newsroom account on X.

How the fake offer borrowed OpenAI’s credibility

The scheme worked through the authority of the sender, not through a convincing cryptocurrency proposition. The affected profile was intended for OpenAI product and policy communications, giving the fraudulent posts a context that an anonymous account could not reproduce.

The unauthorized message presented $OPENAI as a company-backed token and suggested that OpenAI users could claim part of its supply. It also tied ownership to access to future beta programs. These claims converted familiarity with the company into a reason to leave X and interact with an unrelated website.

The destination copied enough of OpenAI’s identity to resemble an official page, while its domain did not belong to OpenAI. Its principal action was a token-claim button leading to a wallet connection. A familiar logo or verified social profile could therefore attract the visitor, but the consequential request occurred on an external domain controlled by someone else.

That distinction is important for creators, who frequently use social accounts to distribute product news, sponsorships, membership offers and limited-access releases. An attacker who controls such a channel temporarily inherits its audience and publishing history. Followers may see the correct handle and established profile while receiving a message the real owner never authorized.

What happened after the posts appeared

The takeover was brief in public view but not immediately resolved. A Bloomberg account of the incident states that the posts appeared at around 7 p.m. New York time, remained visible to some users roughly an hour later and were subsequently deleted. OpenAI was aware of the compromised @OpenAINewsroom account and was examining the incident.

Deletion ended the account’s visible promotion of the offer, but it did not establish whether anyone followed the link or approved a wallet action. The public material reviewed for this update contains no verified victim count, financial-loss figure or technical account of the initial intrusion.

It is therefore inaccurate to describe the episode as a demonstrated breach of ChatGPT, OpenAI’s models or customer conversations. The identified asset was a communications profile hosted on X. No reviewed evidence connects this takeover to access inside OpenAI’s product infrastructure.

The wallet prompt was the consequential step

Opening a page and connecting a wallet are not equivalent to losing assets, and the distinction matters. A wallet connection can disclose an address and prepare an application for further interaction; the greater danger arises when a user signs a malicious message, approval or transaction without understanding the permissions involved.

The available coverage described the fake page as seeking wallet connections, but it did not document what every visitor saw or signed. It would go beyond the evidence to claim that all connections automatically produced theft. The verified warning is narrower: the official-looking post directed users into an untrusted transaction flow where credentials, permissions or assets could be exposed.

The offer also used beta access as an incentive. That tactic is especially relevant in the creator economy, where invitations, early-access programs and platform partnerships can have genuine professional value. The existence of legitimate access programs makes the format plausible; it does not validate a particular link or financial request.

Why verification must extend beyond the account

A corporate handle establishes who normally operates a profile, not who authored every post currently visible on it. When an unexpected announcement asks for money, credentials or wallet authorization, the request needs evidence independent of the social post that delivered it.

The strongest check is whether the same offer appears on the organization’s known website or inside its established product. The destination domain also needs to match the organization’s real domain, rather than merely containing its name. A copied wordmark, polished page and verified sender are all reproducible once an account or web template is under an attacker’s control.

For creators and community operators, this incident also exposes a communications dependency. If one social profile is the only place followers can authenticate an unusual offer, temporary control of that profile gives an attacker both distribution and apparent legitimacy. A separately controlled website, mailing list or second established channel gives the audience somewhere to compare a disputed announcement.

OpenAI’s newer security option has a different scope

Advanced Account Security is an optional setting for eligible personal ChatGPT accounts. It requires passkeys or physical security keys, disables password login and email or SMS recovery, shortens sessions, provides login alerts and lets users inspect active sessions. The protection follows the same login into Codex.

Its stricter recovery design creates a trade-off: enrolled users must retain backup passkeys, security keys or recovery keys because OpenAI Support cannot restore access when all approved methods are lost. The setting may suit creators whose accounts contain unpublished work or connected workflows, but enrollment requires careful custody of recovery material.

These controls should not be presented as OpenAI’s resolution of the 2024 X incident. A ChatGPT security setting does not govern authentication, delegated access or recovery for an organization’s external social-media profile. The historical takeover and the newer product protection concern the same broad risk—unauthorized account access—but apply to different systems.

The lasting lesson is correspondingly precise. OpenAI’s real Newsroom account carried a fake token offer, the posts were removed, and neither the intrusion route nor verified losses became public in the material reviewed here. A trusted identity can justify attention, but it cannot by itself authorize a financial transaction.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0