A megaphone spilling a pile of blank coins in blue halftone, beside the headline X Account Posting Crypto? Stop It Now.

X Account Hacked and Posting Crypto Scams? What to Do

Your X account is posting memecoin, airdrop or giveaway links you never wrote? How to stop the posts, revoke rogue apps and warn followers in Malaysia.

11 min read
Short answer

Treat crypto posts you did not write as a compromise. Change your X password, log out all other sessions and revoke unknown apps in Apps and sessions, then secure your email, delete the posts and turn on two-factor authentication. If you are locked out, use X's regain access form. Followers who paid should call 997.

Summary
  • Crypto giveaway, airdrop or memecoin posts you did not write usually mean someone has your password, an active session or a connected app with posting rights.
  • Change your X password, log out all other sessions and revoke every connected app you do not recognise, because an authorised app has its own access.
  • Secure the email on the account, delete the scam posts, turn on two-factor authentication and post a short warning to your followers once you are back in control.
  • If you are locked out, use X's regain access form from the email linked to the account, and give your username and the date you last had access.
  • Followers who sent crypto or money should call their bank or the NSRC on 997 and make a police report, and nobody legitimate will ask for your password or login codes.
  • Only X can restore a locked or suspended account, help from anyone else is best effort, and some accounts do not come back.
Table of contents14 sections
  1. 01What Should You Do If Your X Account Is Posting Crypto Scams?
  2. 02Why Hacked X Accounts Post Crypto Giveaways
  3. 03How Did They Get In? Three Doors to Close
  4. 04The Lockdown, Step by Step
  5. 05Connected Apps: The Step People Miss
  6. 06Clean Up the Posts, Profile and Messages
  7. 07Turn On Two-Factor Authentication and Reset Protection
  8. 08Warn Your Followers the Right Way
  9. 09Locked Out Instead? Use X's Official Routes
  10. 10Evidence Checklist
  11. 11Mistakes That Keep the Posts Coming
  12. 12If a Follower Sent Crypto or Money
  13. 13When a Case Review Makes Sense
  14. 14Frequently Asked Questions

A follower replies to one of your posts: "Is this really you?" Your X profile is pushing a memecoin, a token airdrop or a giveaway that promises to double any crypto sent to a wallet address. You can still log in, but the posts keep appearing, and some of your followers have already clicked.

The short answer: someone has a way into your account. It might be your password, a logged-in session, or an app you once connected that can post for you. Close all three doors in one sitting, then clean up and warn people. If you are already locked out, X has a separate form for that.

This guide covers the steps in order, the app check most people skip, and what a follower who sent money should do in Malaysia. The same takeover pattern hits YouTube channels too; if yours was renamed and is streaming a giveaway, see our guide to a YouTube channel hacked and streaming crypto.

Last checked: 5 October 2026.

#What Should You Do If Your X Account Is Posting Crypto Scams?

Change your X password, then open "Apps and sessions" in your settings, select "Log out all other sessions" and revoke every connected app you do not recognise. Secure the email inbox linked to X so nobody can reset the password again. Delete the scam posts, turn on two-factor authentication and post one clear warning to your followers. If the password no longer works and resetting fails, use X's regain access form from the linked email address. Only X can restore an account it has locked or suspended.

#Why Hacked X Accounts Post Crypto Giveaways

A random account promising free tokens gets ignored. Your account, with your name and your followers' trust, does not. X's Authenticity policy bans scam tactics used to obtain money, property or private information, naming money-flipping schemes and phishing among them, and it bans malicious links that lead to phishing pages or malware.

The posts tend to follow a few patterns, in English, Bahasa Malaysia or Chinese:

  • A "giveaway" that asks followers to send crypto to a wallet address and promises double back.
  • An "airdrop" or "claim your tokens" link that leads to a page asking people to connect a crypto wallet.
  • A new memecoin presented as your own project, with a contract address to buy.
  • Your display name, profile photo and bio changed to look like a crypto project or a well-known figure.

X's page on compromised accounts lists the signs: posts or Direct Messages you did not send, follows, unfollows or blocks you did not make, a notice that your account information changed, or a password that suddenly stops working.

#How Did They Get In? Three Doors to Close

X says accounts are usually compromised in a handful of ways: you gave your username and password to a malicious app or website, the password was weak or reused, malware on your computer collected it, or you logged in on a compromised network. For crypto posts, three doors matter most.

Signs, likely causes and the fix for each, based on X Help Center pages at the time of writing. More than one may apply.
What you noticeLikely way inWhat closes it
You can still log in and nothing in your settings changedA connected app with posting rights, or a stolen sessionRevoke unknown apps and log out all other sessions in "Apps and sessions"
You recently entered your X password on a page reached from a linkA phishing page that copied your passwordChange the password, then revoke apps and sessions
Posts continue even after a new password and app clean-upMalware on a device you use for X, or an app you missedScan your devices for malware, install security updates and check "Apps and sessions" again
Your password no longer worksThe attacker changed it, and possibly the emailReset the password, check the old inbox for an email change notice, or use the regain access form

#The Lockdown, Step by Step

Do these in one go, ideally on a computer you trust. Skipping one can leave the posts running.

  1. Change your X password from the Password option in settings. Pick a new one you have never used anywhere. If you are logged out, use "Forgot password?" on the login screen.
  2. Open Settings and privacy, then "Apps and sessions". Under Sessions, select "Log out all other sessions". X's apps and sessions page shows the location and time of each login.
  3. In the same section, look at every connected app and its permissions. Select "Revoke access" for anything you do not recognise or no longer use, especially apps with permission to post for you.
  4. Secure the email account linked to X: change its password, sign out other sessions and remove any forwarding rules you did not set. Whoever holds that inbox can reset your X password.
  5. Update the password in any trusted tool that still uses it. X warns that an app holding an old password can trigger temporary lockouts through failed logins.

#Connected Apps: The Step People Miss

Changing the password feels like the fix, so this step is easy to skip. When you tap "Sign in with X" or "Connect to X" on another site, you grant that app access to your account through X's authorisation system, and X says it does not share your password with apps. X says that, depending on its permissions, an app may be able to read your posts, update your profile, post on your behalf and access your Direct Messages. X lists revoking unknown apps as its own step after the password change, so do not rely on the new password alone.

Some fake airdrop, follower boost and analytics sites ask you to connect your X account and can then post for you until you revoke them. X tells you to be especially wary of giving your login to sites promising more followers fast and to apps that post affiliate ads to your timeline.

  • Revoke anything you do not recognise, even if the name sounds official.
  • Revoke apps you connected for a single giveaway, quiz or airdrop.
  • If you ever typed your X password into an app or website rather than an X authorisation page, revoke it and change your password, as X advises.

If posts still appear after this, X suggests scanning your computers for viruses and malware and installing security updates.

#Clean Up the Posts, Profile and Messages

X's compromised account page tells you to delete any unwanted posts made during the compromise. Save evidence first, because followers who lost money may need it.

  1. Screenshot each scam post, reply and pinned post with the date and URL visible, and note the wallet addresses and links used.
  2. Delete the posts, replies and Reposts you did not make, and unpin anything the attacker pinned.
  3. Restore your display name, profile photo, header and bio, and remove any link the attacker added.
  4. Check your Direct Messages for scam links sent to followers, screenshot them, and message those people directly to warn them.
  5. Undo follows and blocks made during the takeover, and confirm the email and phone on the account are yours.

#Turn On Two-Factor Authentication and Reset Protection

Two-factor authentication means a stolen password is not enough on its own. X's two-factor authentication page says you can find it under Settings and privacy, "Security and account access", then "Security", and choose a text message, an authentication app or a security key. After setup, X shows a backup code and recommends you keep it for when you lose your phone or change your number.

  • An authentication app or a security key does not depend on your SIM, which helps if you worry about SIM swap.
  • Store the backup code offline, somewhere only you can reach. Never send it to anyone.
  • Turn on "Password reset protection" under Security. X's account security tips say this makes anyone requesting a reset enter your email or phone number first.
  • Watch for login alerts. X says it sends a notification when it detects a suspicious login or a new device.

#Warn Your Followers the Right Way

A short, plain warning protects people who saw the posts. Post it on X once you are in control, and on any other channel you use.

My account was compromised earlier today. The crypto giveaway and token posts were not from me. Do not send crypto, connect a wallet or click those links. If you did, contact your bank or call 997.
  • Pin the warning for a few days so latecomers see it.
  • Ask followers to report scam posts they find with "Report post", which X's reporting page describes. Good-faith reports are fine.
  • Do not ask people to mass report anything. X's Authenticity policy prohibits submitting duplicate or false reports in large numbers.
  • If followers were scammed through your account, our guide to friends scammed from a hacked account covers how to support them.

#Locked Out Instead? Use X's Official Routes

If the attacker changed your password, try "Forgot password?" first. X's security tips say it emails the previously used address whenever the account's email is changed, so search that inbox and its spam folder for the notice.

If the reset fails, X says to submit a support request using the email address linked to the compromised account, including your username and the date you last had access. The regain access form is where that starts. If the form says the browser is not supported, try another browser. When the email itself was swapped, our guide to an X account hacked with the email changed walks through that situation.

X's Authenticity policy says scam posts can lead to limits or suspension. If that happens after a hack, explain the timeline in your appeal. X makes the final call.

#Evidence Checklist

  • Screenshots of every scam post, reply and Direct Message, with the date and URL visible.
  • The wallet addresses, token names, contract addresses and links the attacker used.
  • Login alerts and email change notices from X.
  • A list of the apps you revoked and the sessions you logged out, with the time.
  • Your username, the email and phone on the account, and the date you last had normal access.
  • Any X support or report reference numbers.

#Mistakes That Keep the Posts Coming

  • Changing the password but never revoking connected apps.
  • Skipping "Log out all other sessions", leaving the attacker's phone signed in.
  • Leaving the email account unsecured, so the attacker resets X again.
  • Replying to accounts that offer to recover your X account or your followers' crypto.
  • Deleting posts before saving screenshots that followers may need for a police report.

#If a Follower Sent Crypto or Money

This is about money, not X. The government's NSRC 997 page lists cryptocurrency and investment scams among the cases the National Scam Response Centre handles. It tells victims to call 997 within 24 hours of discovering the scam, contact their bank, and make a police report at the nearest station.

  1. Stop sending anything more, and do not sign further wallet requests from the scam site.
  2. Call the bank that sent the money, or call 997. For a crypto exchange, contact it through its official app or website only.
  3. Make a police report and bring screenshots of the post, the wallet address and the transaction details.
  4. Expect follow-up scams offering to recover the lost crypto. They are scams too.

Nobody can promise the money comes back. A phishing page used in the takeover can also be reported to CyberSecurity Malaysia's Cyber999, by online form, email, phone or its mobile app. If your phone suddenly shows "No service" while X codes stop arriving, ask your carrier from another phone whether your SIM was replaced.

#When a Case Review Makes Sense

If you still have access, you can work through the steps above yourself. A second opinion helps when you are locked out and the email has changed, when X suspended the account over the scam posts, or when the account carries a business or a large following. SocialSafe by AwareXone, our recovery service, reviews your case first and tells you honestly whether an official X route is still open. We use the same X forms described here, the work is best effort, and some accounts are not restored. You can read how we handle X account recovery, and our Trust Center explains what we will never ask for, starting with your password and codes.

#Frequently Asked Questions

Why is my X account still posting crypto after I changed my password?
A connected app, a session you have not logged out or malware may still have access. X lists revoking unknown apps as a separate step from changing the password, so revoke them and log out all other sessions in "Apps and sessions". If the posts continue, X suggests scanning your computers for viruses and malware.
My friend's X account is posting a crypto giveaway. What should I do?
Tell your friend through a channel you already trust, such as a phone call. Report the post once with "Report post" and do not click the link, connect a wallet or send anything.
Can X suspend my account for scam posts I did not make?
It can. X's Authenticity policy lists limits and suspension as enforcement options for scam content. If that happens, explain in your appeal when the account was compromised and what you did to secure it.
Is a crypto giveaway on X ever real?
Treat any post asking you to send crypto to receive more back as a scam. X's Authenticity policy names money-flipping schemes among the scam tactics it prohibits.
Can AwareXone stop the crypto posts for me?
If you still have access, you can usually stop them yourself with the steps here. If you are locked out, we review the case and help you use X's official forms, without ever asking for your password or codes.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: X account recovery.