Twitter Hacker Is a BitMEX Trader, On-Chain Data Suggests
Whoever is responsible for Wednesday's Twitter hack was deep into the cryptocurrency space, with the BitMEX receipts to prove it.

None of the roughly 13 bitcoin
But whoever it was is deep into the cryptocurrency space, with the BitMEX receipts to prove it, according to preliminary analysis from Samourai Wallet's research arm, OXT Research. (A pastebin can be found here.)
“Confirmed, no signs of mixing. Majority of funds spent 1 or two hops and [are] now parked,” Samourai said in a Twitter DM to CoinDesk. “Really curious what their cash-out plan is.”
As of 14:00 UTC, the funds in at least one address are already under the control of Coinbase, Samourai added.
Read more: Full coverage of Twitter Hack 2020
“Based on the history of the first destination address of the cryptoforhealth scam addresses, the scammers have a history of gambling on Bitmex and Coinbase usage,” Samourai researcher Ergo said in a Tweet.
“This is peak crypto,” Ergo added.
No coin-mixing involvement (yet)
Overall, Samourai says the hacker only used three Bitcoin addresses and has not sent any funds through a mixing service, as data provider CryptoQuant had previously tweeted. (CryptoQuant has since told CoinDesk it no longer believes the funds have been mixed.)
"Always a possibility the address is an unlabeled mixer, but I don't see any hints, and one-time use addresses are very common in general and not a definitive pattern for mixers," Ergo told CoinDesk.
Those addresses, however, linked to other addresses that Samourai tracked to the popular crypto derivatives platform BitMEX.
“Everything from the first address is being spent to this address 1Ai52Uw6usjhpcDrwSmkUvjuqLpcznUuyF, which looks to have been first funded via BitMex,” Samourai said.
Read more: Samourai Wallet Releases Privacy-Enhancing CoinJoin Feature
Tracking the Twitter hack funds through Bitcoin exchanges
On-chain data allows services to track where funds are moving. In this case, the address had previously been used by a BitMEX trader for moving funds on and off the platform. However, BitMEX has less stringent ID policies, also known as Know Your Customer (KYC), for trading on its domain. So BitMEX may not be so helpful in finding the perpetrator.
BitMEX did not return requests for comment by press time.

“At best investigators can subpoena any relevant account info including IP addresses[;] from there, they can glean some additional info from on-chain data including source of funds,” Ergo said in a private message.
Coinbase, on the other hand, has very strict KYC policies. Ergo said the best chance of identifying the hacker comes from Coinbase.
"OXT Reasearch has also noted a small spend of scammed coins to Binance. Other than the history of 1Ai52Uw6usjhpcDrwSmkUvjuqLpcznUuyF, the links to exchanges and known entities remain minimal," Ergo said.

More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
Coinbase Expands Reach of Stablecoin-Based AI Agent Payments Tool

The updated protocol, x402 V2, allows developers to combine payments, enable secure wallet access, and add new features via a clean, modular design.
What to know:
- Coinbase has released the latest version of its stablecoin-based payments protocol for AI agents, making it easier to extend and plug in the autonomous payments system.
- The new version adds wallet-based identity, automatic API discovery, dynamic payment recipients, and support for more chains and fiat.











