In Brief:
- Portal says an attacker took control of its X account overnight and used it to publish a phishing link built to hit connected wallets.
- According to the team, the breach was spotted right away, the account was locked down, access was restored and the malicious post was removed.
- Still unanswered: how the intruder got in, how long the link remained visible, and whether any wallets were drained.
An attacker seized Portal's X account and used it to publish a phishing link aimed at connected wallets, the project disclosed on Friday.
“The Portal X account was temporarily compromised last night. A malicious phishing link was posted, attempting to target connected wallets,” Portal said in a post from the recovered account.
Security Update
The Portal X account was temporarily compromised last night. A malicious phishing link was posted, attempting to target connected wallets.
Our team detected the breach immediately. We locked down the account, restored access, and deleted the malicious post.@PortalView on X ↗
“Our team detected the breach immediately. We locked down the account, restored access, and deleted the malicious post,” the post said.
Left out of the notice: the entry point the attacker used, the amount of time the post stayed up before deletion, and the number of users who engaged with the link. No loss figure has been published either, and the project has not stated whether any wallets were emptied. No outside security firm was named as helping with the review.
What the account posted
How Portal phrased its notice suggests a wallet drainer was involved rather than a credential harvester. Campaigns that “target connected wallets” generally funnel visitors to a cloned site carrying a connect prompt, then serve a signature request that surrenders token approvals. Once those signatures settle on chain, there is no clawing them back.
No domain was provided for the deleted link, so holders have nothing concrete to cross-reference against their transaction history. Users who signed anything after encountering an overnight post from the account will have to revoke approvals themselves.
Portal has been a phishing target before
Impersonation attempts around the PORTAL ticker go back years. A wallet drainer marketed as a “Check $PORTAL Eligibility” tool, wrapped around a bogus airdrop checker, was documented by security vendor PCrisk, which said the pages behind it circulated via stolen social media accounts and compromised WordPress sites.
The notice published this week describes that same distribution route — except this time the account doing the promoting belonged to Portal itself.
Part of a longer run of takeovers
Accounts belonging to crypto projects have been falling throughout the year. On Feb. 3, Arbitrum DAO confirmed that attackers had seized its governance account, @arbitrumdao_gov, and used it to push fake airdrop links to gov-arbitrum[.]com, a page fronted by a connect wallet prompt.
That campaign relied on eligibility framing, dangling rewards for “real users” who had bridged, swapped and voted while casting the rest as farmers and opportunists. Arbitrum warned users away from anything the account posted, stated that the protocol and user funds were unaffected, and eventually regained the handle. Reported losses remained limited.
BNB Chain’s official account was also targeted and turned into a promotion channel for a bogus “BNB HODLer Airdrop” until the team recovered it. Andreessen Horowitz likewise got its account back after attackers pushed a fraudulent Solana token to an audience of more than 850,000 followers; the token surged before dropping close to 90%.
Animoca Brands acknowledged that the account of co-founder Yat Siu had been hijacked and used to promote a fraudulent Pump.fun token trading under the Mocaverse name. At least 15 accounts were hit by the same group, according to a tally from investigator ZachXBT.
How the accounts fall
An ongoing campaign against high-value X accounts, tracked by SentinelLabs, operates by posing as X’s own support staff. Victims receive a copyright infringement notice, click through to a lookalike page and reset their credentials there — handing over two-factor details in the process. Alongside crypto teams, the net has caught journalists, political figures, an X employee and owners of short handles.
Control of Portal’s account has been returned to the team. No security firm, exchange or blockchain investigator has released an independent account of the incident as of publication, leaving Portal’s own post as the sole description of events.















STAY ALWAYS UP TO DATE