SubscribeBTCSCAMWallet Test
Front page / Account takeover · DOJ
elevatedAccount takeover · DOJ

A fake tweet, a real SIM swap: how one hacker moved the Bitcoin price

Eric Council Jr. printed a fake ID, walked into an AT&T store, and hijacked the SEC's X account to post a phantom ETF approval. He got 14 months; the market got whiplash.

H
HexDiver
Volunteer Analyst · JAN 9, 2024 · 5 min read
Painting: Renaissance archive · Source: U.S. Department of Justice

On the afternoon of January 9, 2024, the official X account of the U.S. Securities and Exchange Commission, @SECGov, announced that the agency had approved spot bitcoin exchange-traded funds. Within minutes bitcoin jumped more than $1,000, per the Justice Department. The post was a fake — the account had been hijacked.

SEC Chair Gary Gensler said within the hour that @SECGov had been compromised and that no approval had been granted; the genuine decision came a day later, on January 10. The brief spike, and the slide that followed once the SEC corrected the record, were exactly the kind of whipsaw a market manipulator hopes to create.

The method was old-fashioned identity theft dressed for the crypto age. According to the Justice Department, Eric Council Jr., 26, of Athens, Alabama, used a portable ID-card printer to make a fake driver's license, then impersonated a victim at an AT&T store in Huntsville to trigger a SIM swap — moving the phone number tied to the @SECGov account onto a device he controlled.

With the number captured, Council bought a new iPhone at a nearby Apple store and received the account's password-reset codes, prosecutors said. He handed access to co-conspirators, who posted the phantom ETF news. For SIM-swap jobs like this one he was paid in bitcoin, earning roughly $50,000 in all, per prosecutors — funds later subject to forfeiture.

Old fraud, faster payout

SIM swapping exploits the softest link in phone-based security: the person at the carrier counter. Once an attacker controls your number, SMS one-time codes and password resets flow straight to them — which is why security teams keep urging a move away from text-message two-factor authentication toward authenticator apps and hardware keys.

Council pleaded guilty in February 2025 to conspiracy to commit aggravated identity theft and access device fraud. On May 16, 2025, a federal court in Washington, D.C., sentenced him to 14 months in prison and three years of supervised release, per the DOJ. He had been arrested in June 2024, allegedly attempting another SIM swap; investigators said a search turned up fake-ID templates and incriminating messages. Interim U.S. Attorney Jeanine Ferris Pirro said such schemes threaten the financial security of ordinary citizens, financial institutions and government agencies.

**Harden your accounts against takeover** - Move two-factor authentication off SMS to an authenticator app or a hardware security key. - Ask your mobile carrier to add a port-out PIN or account lock that blocks unauthorized SIM swaps. - Treat any single account's market-moving claim — even a regulator's — as unconfirmed until corroborated elsewhere. - Watch for password-reset codes or 'SIM changed' alerts you didn't request; they can signal a takeover in progress.

The episode's blunt lesson: even a verified government account is only as secure as the phone number sitting behind it.

— Sources: [U.S. Department of Justice](https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin) · [Cointelegraph](https://cointelegraph.com/news/judge-sec-hacker-eric-council)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING