Cybercriminals Exploit X Ads to Promote Fake Crypto Schemes

Fake 'Apple iToken' Cryptocurrency Targets Investors
On May 8, 2025, cybersecurity researchers uncovered a sophisticated cryptocurrency scam exploiting X’s advertising system. Fraudsters are using spoofed display URLs to trick users into believing they are visiting legitimate websites, such as CNN.com, while actually redirecting them to malicious cryptocurrency scam pages.

Fake ‘Apple iToken’ Cryptocurrency Targets Investors

One of the most deceptive elements of this scam is the promotion of a fake cryptocurrency called “Apple iToken.” The fraudulent ads falsely claim that Apple is launching a new digital token, even featuring fabricated endorsements from Apple CEO Tim Cook. When unsuspecting users click on the ad, they are redirected to a crypto scam website designed to steal funds.

How Cybercriminals Manipulate X’s Advertising System

Security experts at Silent Push revealed that scammers are exploiting X’s URL validation system to display trusted domain names in advertisements while secretly redirecting victims to malicious sites.

The attackers use URL shorteners to initially direct X’s bots to a legitimate website like CNN.com. Once the ad is approved, they change the destination URL to a fraudulent crypto investment page.

A Growing Network of Cryptocurrency Scams

Researchers have identified nearly 90 scam websites dating back to 2024, all linked to the same threat actor group. These sites offer 22 different cryptocurrency wallet options for victims to send funds, making it difficult to track and recover stolen money.

Financial Losses and Rising Scam Cases

According to cybersecurity reports, cryptocurrency scams have resulted in over $3 billion in losses globally in 2024, with social media-based fraud accounting for nearly 40% of cases. Experts warn that X’s advertising loophole could lead to millions of dollars in additional losses if not addressed.

Experts Urge Caution Against Crypto Investment Scams

Cybersecurity analysts warn that social media-based financial scams are becoming increasingly sophisticated.

A Silent Push spokesperson stated, “This attack demonstrates how cybercriminals continue to find creative ways to abuse legitimate platform features. Users should always verify investment opportunities before sending funds.”

About William Ross 451 Articles
I am a cryptocurrency enthusiast and writer with over five years of experience in the industry. I have been following the development and innovation of Bitcoin and Ethereum since their inception, and I enjoy sharing my insights and analysis with readers. I have written for various reputable platforms, such as CoinDesk, Cointelegraph, and Decrypt, covering topics such as market trends, regulation, security, and adoption. I believe that cryptocurrency is the future of finance and technology, and I am passionate about educating and informing people about its benefits and challenges.

Be the first to comment

Leave a Reply

Your email address will not be published.