In Brief:
- Portal said its X account was compromised overnight and used to post a phishing link aimed at connected wallets.
- The team said it caught the breach immediately, locked down the account, restored access and deleted the malicious post.
- Portal hasn’t disclosed how the attacker got in, how long the link stayed up or whether any wallets were drained.
Portal’s X account was compromised and used to post a phishing link that targeted connected wallets, the project said Friday.
“The Portal X account was temporarily compromised last night. A malicious phishing link was posted, attempting to target connected wallets,” Portal said in a post from the recovered account.
Security Update
The Portal X account was temporarily compromised last night. A malicious phishing link was posted, attempting to target connected wallets.
Our team detected the breach immediately. We locked down the account, restored access, and deleted the malicious post.@PortalView on X ↗
“Our team detected the breach immediately. We locked down the account, restored access, and deleted the malicious post,” the post said.
Portal didn’t say how the attacker gained access, how long the post was live before it came down, or how many people interacted with the link. The project also hasn’t published a loss figure or said whether any wallets were emptied. It named no third-party security firm assisting with the review.
What the account posted
The wording of Portal’s notice points to a wallet drainer rather than a credential harvester. Posts that “target connected wallets” typically route users to a spoofed site with a connect prompt, then push a signature request that hands over token approvals. Signatures like that settle on chain and can’t be clawed back.
Portal gave no domain for the link it deleted, which leaves holders without a string to check their transaction history against. Anyone who signed anything after seeing a post from the account overnight would need to revoke approvals manually.
Portal has been a phishing target before
The PORTAL ticker has drawn impersonation attempts for years. Security vendor PCrisk documented a “Check $PORTAL Eligibility” wallet drainer built around a fake airdrop check, and noted the pages behind it were pushed through stolen social media accounts and hijacked WordPress sites.
That is the same distribution method described in this week’s notice, with the difference that the account doing the pushing was Portal’s own.
Part of a longer run of takeovers
Crypto project accounts have been falling all year. Arbitrum DAO confirmed on Feb. 3 that its governance account, @arbitrumdao_gov, had been taken over and used to post fake airdrop links pointing to gov-arbitrum[.]com, a site fronted by a connect wallet prompt.
The copy on that one leaned on eligibility language, promising rewards to “real users” who had bridged, swapped and voted, while framing everyone else as farmers and opportunists. Arbitrum told users not to click anything from the account, said the protocol and user funds were untouched, and later recovered the handle. Reported losses stayed limited.
BNB Chain’s official account was hit too, and used to promote a fake “BNB HODLer Airdrop” before the team took it back. Andreessen Horowitz recovered its account after attackers pitched a fraudulent Solana token to more than 850,000 followers; the token spiked, then fell close to 90%.
Animoca Brands confirmed that co-founder Yat Siu‘s account had been hijacked to shill a fraudulent Pump.fun token trading on the Mocaverse name. Investigator ZachXBT counted at least 15 accounts hit by the same group.
How the accounts fall
SentinelLabs has tracked an active campaign against high-value X accounts that works by impersonating X’s own support staff. Targets get a copyright infringement notice, follow it to a lookalike page and reset their credentials there, two-factor details included. Journalists, political figures, an X employee and holders of short handles have all been swept up alongside crypto teams.
Portal’s account is back under the team’s control. As of publication no security firm, exchange or blockchain investigator has published an independent account of the incident, and Portal’s own post remains the only description of what happened.