Loading article…
Peru's Ministry of Economy and Finance X account was compromised on September 14, promoting a fake $HYLO token. This follows a trend of government and tech
Peru’s Ministry of Economy and Finance (MEF) confirmed on September 14 that its official X account was compromised by crypto scammers who promoted a fake token called $HYLO, urging users to check for allocations before a supposed September 25 launch [1]. The incident highlights a growing pattern of high-profile social media accounts, including government entities and tech companies, being exploited to push fraudulent cryptocurrency schemes [1, 4].
| At a glance | |
|---|---|
| Incident | Peru MEF X account hacked [1] |
| Scam promoted | Fake $HYLO token [1] |
| Claimed launch date | September 25 [1] |
| Broader trend | Government/tech accounts targeted [1, 4] |
The attackers used the MEF's official X platform to post messages claiming token allocations specifically for Peruvians and setting a September 25 date for claims and trading [1, 2]. The ministry quickly clarified that these posts were unauthorized, advising the public to disregard them, and activated security measures to regain control, leading to the deletion of the fraudulent messages [1, 2]. The MEF has not disclosed how the attackers gained access or identified those responsible, nor has it reported any financial losses connected to the incident [1, 2].
This hack aligns with a recurring pattern in Latin America and beyond, where official government accounts are compromised to lend credibility to fraudulent crypto schemes [1]. The U.S. Federal Trade Commission (FTC) reported that business and government impersonation scams accounted for $133 million in reported cryptocurrency losses between January 2021 and March 2022, with 49% of crypto fraud reports originating on social media during that period [2].
The MEF incident follows a series of similar compromises targeting high-profile X accounts. OpenAI's official Newsroom X account was recently hijacked by crypto scammers promoting a fake "$OPENAI" blockchain token, linking to a phishing site designed to steal users' crypto wallet credentials [3, 4, 5]. This was not an isolated event for OpenAI, as the accounts of CTO Mira Murati, chief scientist Jakub Pachocki, and researcher Jason Wei were also targeted in previous months to advertise the same bogus token [3, 4]. Scammers in these cases reportedly used "crypto drainer" tools to redirect NFTs and tokens from victims' wallets [4].
Other notable incidents include the Instagram account of McDonald’s and its senior marketing director being hacked to promote a fake meme coin named Grimace [4]. In 2020, hackers exploited X accounts belonging to Apple, Elon Musk, and Joe Biden to solicit Bitcoin transactions under false pretenses [4]. The FTC reported that Americans lost $5.6 billion to cryptocurrency scams in 2023, a 45% increase from the previous year, with nearly $2.5 billion lost in the first half of 2024 alone [4].
The repeated targeting of official and high-profile social media accounts underscores the ongoing challenge of digital security and the persistent efforts by scammers to exploit trust in established entities for financial gain.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 5 outlets · Sep 15, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.