A new and highly deceptive financial scam has surfaced on X/Twitter, exploiting a significant flaw in the platform’s advertising URL feature.
Security experts have identified a dangerous scheme that manipulates users by showing familiar and trusted website names in ads, only to redirect them to fraudulent cryptocurrency scam sites.
The method behind this attack exploits a vulnerability in X/Twitter’s URL system, allowing cybercriminals to display one domain to the platform’s crawlers while actually sending users to a completely different site.
The latest version of this scam was uncovered on May 1, 2025, when fake ads for a non-existent “Apple iToken” cryptocurrency began circulating on X/Twitter.
What made these ads so convincing was the use of a display URL claiming to be from “CNN.com,” creating a sense of trust. However, clicking the link led users straight to a fake cryptocurrency site designed with an Apple-like appearance, aiming to steal users’ funds.

An ad campaign leveraging the Apple brand, a fake “iToken” product, and a deceptive “From CNN[.]com” landing page has emerged, exploiting a critical flaw in X/Twitter’s URL handling system (Source – Silent Push).
Researchers at Silent Push uncovered this advanced scam through their monitoring systems and recognized it as a notable progression in social media-driven financial fraud.
Their investigation revealed that the attackers behind this operation have developed nearly 90 identical websites since 2024, each designed to lure cryptocurrency investors with nearly identical financial scams.
Silent Push experts highlighted that this attack exemplifies how cybercriminals are increasingly creative in exploiting legitimate platform features. “This campaign is a clear example of how cybercriminals continue to manipulate trusted systems for their gain,” they noted in their findings.
The scam specifically targets cryptocurrency enthusiasts by masquerading as a new Apple initiative. The fraudulent sites even feature fake endorsements from Apple CEO Tim Cook to add a layer of credibility to the ruse.
The attack’s complexity is further demonstrated by its infrastructure, which includes 22 different cryptocurrency wallet addresses, each linked to a different website, making it harder to track or attribute.
Technical Breakdown of the URL Spoofing Mechanism
At the heart of this attack is a manipulation of how X/Twitter processes URLs in its ads. According to the Silent Push report, the attackers employ a multi-step redirection strategy that bypasses X/Twitter’s URL verification protocols.
The scam begins with the attackers using a URL shortener (such as Bitly) to mask the true destination, initially redirecting to a trusted domain like CNN.com. When X/Twitter’s crawler scans the ad to generate a preview, it sees the legitimate CNN domain and displays it in the ad preview as “From CNN.com.”
Once the ad is approved, the attackers change the destination of the shortened URL to point to their malicious website, allowing them to deceive users into clicking on the fraudulent link.

This attack establishes a sophisticated chain of redirects: X/Twitter ad → Bitly shortener → Secondary X/Twitter URL → Final fraudulent website (such as ipresale.world or similar domains).
According to Silent Push’s analysis, the first Bitly link in this campaign was created on May 1, 2025, at 19:22 UTC, just moments before the ad was set live.
The redirection ultimately sent users to deceptive domains like “ipresale.world” and “itokensale.live,” which exploited Apple’s branding to promote fictitious cryptocurrency presale events.
This method echoes a similar tactic reported by Bleeping Computer in March 2024, where cybercriminals used the same redirection technique to spoof other reputable websites like forbes.com. This suggests that attackers continue to take advantage of this vulnerability, despite it being previously acknowledged.




