SEC's X Account Hacked to Falsely Say Bitcoin ETF Approved

News January 10, 2024 at 09:18 AM
Share & Print

A highly anticipated decision by the U.S. Securities and Exchange Commission on whether to approve a spot-Bitcoin exchange-traded fund quickly morphed into a major cybersecurity incident on Tuesday.

The SEC's X account was compromised and a fake post claiming that the agency had green lit plans for the products fueled a brief surge in the price of the world's biggest cryptocurrency.

It also has sparked an investigation by U.S. authorities into how a social media account at Wall Street's main regulator was compromised.

"It really shows the breadth and frequency of cyberattacks," said Kurt Gottschall, a partner at law firm Haynes Boone and former SEC regional director. "The irony here is that the SEC has not shown much sympathy to public companies and asset managers that have experienced cybersecurity incidents."

The breach gave fodder to crypto faithful who have long viewed the commission's chair, Gary Gensler, as an enemy due to his zeal to rein in the industry.

The irony of a cybersecurity incident befalling a regulator that's repeatedly warned of crypto's online vulnerabilities was not lost on critics who have spent years waiting for the SEC to approve a Bitcoin ETF.

Traders have been speculating for weeks that the agency could approve several of the products as soon as Wednesday.

Investigation

In statements late Tuesday, the regulator said that it would work with law enforcement to investigate the incident, the unauthorized access had been terminated, and that the post wasn't made by the SEC or its staff.

In a separate statement, Gensler clarified that no decision on ETFs had been made.

"The @SECGov twitter account was compromised, and an unauthorized tweet was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products." — Gary Gensler (@GaryGensler) January 9, 2024

The SEC said that there was unapproved activity on the @SECGov X account "by an unknown party for a brief period of time shortly after 4 pm ET" on Tuesday.

After the fake post was removed, Joe Benarroch, head of business operations at X, said in a statement that the "account is secure and we are investigating the root cause."

The social media service said in a post that "an unidentified individual" compromised the SEC's account by acquiring control of an associated phone number. It added that the account didn't have two-factor authentication enabled at the time of the incident.

Such authentication adds an extra layer of security that's become increasingly common as cyberattacks proliferate.

"We can confirm that the account @SECGov was compromised and we have completed a preliminary investigation. Based on our investigation, the compromise was not due to any breach of X's systems. but rather due to an unidentified individual obtaining control over a phone number… ." — Safety (@Safety) January 10, 2024

The SEC didn't immediately respond to an emailed message sent outside regular business hours seeking comment on X's initial assessment.

Meanwhile, Republican Senators JD Vance and Thom Tillis in a letter demanded an explanation for the SEC's "errant" post. They are seeking a briefing by the SEC and answers to questions no later than Jan. 23.

Decision Due

About a dozen companies have applied to list ETFs backed by Bitcoin in the U.S.

The SEC has until Jan. 10 to take action on at least one of those applications, and crypto insiders have speculated the regulator will use that date to announce a slew of decisions at once.

There are two technical requirements that must be fulfilled before a spot-backed Bitcoin ETF can start trading.

First, the SEC must sign off on so-called 19b-4 filings by the exchanges that would list the ETFs. Second, the regulator must approve the relevant S-1 forms, which are the registration applications from the would-be issuers — a list that includes BlackRock Inc. and Fidelity.

The SEC is planning to vote on the exchanges' filings, the 19b-4s, this week, Bloomberg News has reported. The regulator may or may not take action on the issuers' applications, the S-1s, around the same time.

If the SEC grants both sets of required approvals, the ETFs could start trading as soon as the next business day.

ETF Controversy

The SEC under Gensler and his Trump-era predecessor, Jay Clayton, has previously refused to allow such a product to launch, citing concerns about investor protection and the potential for market manipulation.

However, speculation has been mounting since August, when the SEC lost a key legal fight against crypto asset manager Grayscale Investments, that the regulator will have to acquiesce to the growing clamor for the product.

Hype about an approval has been rampant on social media. Bitcoin surged as much as 10% on Oct. 16 when a crypto news site incorrectly posted on X that BlackRock had been approved to list a spot ETF.

About $85 million of mostly bearish trading positions were liquidated during the surge, which quickly reversed.

Credit: Adobe Stock

Copyright 2024 Bloomberg. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Related Stories

Resource Center