← Radar

Incident case file

Sign in to watch

Jadoodoo — Hacked KOL X Account Distributes Phishing DMs to Crypto Followers

Incident date June 1, 2026

0 views

PausedNA (social engineeringmulti-chain victims)Social Engineering / PhishingCluster: JADOODOO-PHISH-2026-06

Estimated loss

$5K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

25%

Facts and investigation

Attacker: MISSING — attacker identity not publicly disclosed | Attack vector: X/Twitter account takeover of @jadoodoo_ (crypto KOL) via suspected SIM swap, credential phishing, or session hijack | Phishing DMs sent to followers containing malicious links leading to fake crypto platforms or wallet drainer scripts

Funds moved to: MISSING — individual victim losses not publicly traced. GoPlus Security estimates cumulative losses across victims at approximately $5,000. Phishing links designed to steal wallet credentials or trick users into signing malicious approval transactions (infinite approval drainers).
MISSING — no attacker wallet addresses publicly disclosed by GoPlus or SlowMist. Victim wallets: unknown. The attack leveraged the trusted reputation of KOL @jadoodoo_ to distribute phishing links via Direct Messages to followers. Multiple KOLs reportedly victimized. GoPlus Security (@GoPlusSecurity / @GoPlusZH) issued the public alert on June 1 2026. Incident logged in SlowMist Hacked under attack method 'Account Hacked'.

Timeline: June 1, 2026 — The X/Twitter account of crypto key opinion leader Jadoodoo (@jadoodoo_) is compromised by an unknown attacker. The attack method is suspected to involve SIM swapping, credential phishing, or session token theft. June 1, 2026 — Using the compromised account, the attacker sends phishing links to the KOL's followers via Direct Messages, posing as legitimate collaboration offers or project announcements. Victims who click the links are directed to fake crypto platforms designed to steal wallet seeds or trick users into signing malicious infinite-approval transactions. June 1, 2026 — GoPlus Security detects the account compromise and issues a public alert. The alert is relayed by SlowMist Hacked. Estimated cumulative losses to victims: approximately $5,000. Multiple KOLs reportedly among the victims. Post June 1, 2026 — No further public details on recovery of the account, attacker identity, or individual victim losses. Incident classified by SlowMist as 'Account Hacked' with $5,000 loss.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)