/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A look at the booming market for bots that steal 2FA codes, often using SMS services like Twilio, to break into Coinbase, Amazon, PayPal, and bank accounts

VICE Joseph Cox

Context & Ripple Effects

This report closes a loop that VICE opened months earlier, when a hacker paid just $16 to a company called Sakari to reroute a reporter's texts and walk straight through his SMS-based logins. What was then a one-off demonstration has since become an industrialized market: bots that automate code interception against Twilio-style SMS plumbing, aimed at Coinbase, Amazon, PayPal, and bank accounts.

The losses are no longer hypothetical — Coinbase disclosed that a threat actor exploited its SMS multi-factor authentication to steal cryptocurrency from 6,000 customers over roughly three months, and Twilio later confirmed attackers used its own breach to generate login codes for Authy users. The bot market described here is the retail layer of that same supply chain.

First-order effects

  • Coinbase, Amazon, PayPal, and consumer banks face automated account-takeover attempts at scale, with SMS 2FA functioning as the weakest door rather than a safeguard — Coinbase's 6,000-customer SMS MFA theft shows the direct financial exposure.
  • Twilio and similar messaging providers find their legitimate bulk-SMS infrastructure repurposed as attack tooling, putting their enterprise reputation and compliance posture on the line.

Second-order effects

  • Consumer platforms are pushed to deprecate SMS as a second factor in favor of app-based or hardware-backed codes, shifting authentication costs onto users and support teams while shrinking demand for carrier-grade SMS delivery.
  • Regulators face renewed pressure over who can buy SMS rerouting and messaging tools, following the Sakari case where a $16 purchase defeated a reporter's entire account stack.

Third-order effects

  • If SMS interception keeps scaling, the industry's trust model migrates away from anything routed through telecom networks — a shift already visible beyond codes, as scammers now bypass banks' KYC checks with stolen biometrics and virtual cameras (facial-scan bypasses), suggesting identity itself becomes the contested layer.
  • Telecom-adjacent intermediaries like Twilio and small carriers such as Fink Telecom — implicated when a whistleblower revealed 1M+ 2FA messages passing through it — become systemic risk nodes whose security failures propagate to every service relying on them for out-of-band verification.

The trend: Authentication is migrating off SMS and telecom-mediated channels entirely, as the same infrastructure that delivers codes becomes the cheapest way to steal them.

Discussion

  • @josephfcox Joseph Cox on x
    These bots are not just for SMS-based 2FA. Can work for app-based too such as Google Authenticator. Seen bots that target Amazon, PayPal, Apple Pay, Venmo, Bank of America, Chase, etc https://www.vice.com/... https://twitter.com/...
  • @motherboard @motherboard on x
    With bots that cost only a few hundred dollars, anyone can start getting around multi-factor authentication, a security measure that many members of the public may assume is largely secure. https://www.vice.com/...
  • @rzol Rita Z on x
    Great reporting! This is among the most realistic phone scams I've heard to trick people into giving up credentials and 2FA codes. Innovating on MFA (and getting rid of pwds in the long run) is key. #infosec #2Fac https://twitter.com/...
  • @josephfcox Joseph Cox on x
    “The bot is great for people who don't have social engineering skills,” one OTP bot seller said. Not everyone is “comfortable and persuasive on the phone you see.” https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    The ecosystem of these OTP bots is already pretty varied. Contacted one in around August, it went dark response, but now points to another similar bot. https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    The calls from the bot are persuasive. Someone is trying to use your PayPal account, please verify you didn't send that money. Enter the code we just texted you (at same time, hacker triggers a legit 2FA code from PayPal). Sense of urgency likely effective https://www.vice.com/..…
  • @motherboard @motherboard on x
    The bots convincingly and effortlessly help hackers break into Coinbase, Amazon, PayPal, and bank accounts. https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    The bots are super simple to use. Enter the target's number, and the platform you're trying to break into. Bot handles the rest and then gives you the code too. Here's what it looks like https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Contacted a wealth of orgs targeted by the bots (Amazon, Apple, PayPal, Bank of America, Chase, Coinbase) and asked if they support hardware security keys. Only one said they did, Coinbase. As piece says, raises Qs on whether platforms need to do more https://www.vice.com/... htt…
  • @josephfcox Joseph Cox on x
    As for how they work, the bots use either Telegram or Discord. On the backend are sites like Twilio, which can send automated messages and calls. Twilio confirmed it is seeing OTP bots on its platform and taking them down https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Piece includes video of one of the bots in action. Very easy for anyone to use, now essentially any level of skill fraudster can try to bypass 2FA. Raises Qs on whether services need to do more than SMS/app 2FA https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    New: underground trade of bots that steal your 2FA codes. Bot places convincing automated call to target. Victim enters code, gets fed to hacker instantly. Dramatically lowers the barrier of entry for bypassing 2FA, no social engineering skills needed https://www.vice.com/...
  • @spencerdailey Spencer Dailey on x
    stop it Paypal, you're drunk. (How does a service that deals with money not think it's a terrible idea to let users log in with just SMS?) https://twitter.com/...
  • @racheltobac Rachel Tobac on x
    Scammers don't need social engineering skills to steal OTP / 2FA codes — a scam bot can do it for them. How to protect? 1. Orgs need to give users option for FIDO security keys 2. Educate on this scam method 3. Help others use FIDO keys if a match for them https://www.vice.com/..…
  • @timmarchman Tim Marchman on x
    Fraudsters are using inexpensive robots to trick people into handing over their 2FA codes: https://www.vice.com/...
  • @jason_koebler Jason Koebler on x
    Automated voice theft of two factor codes under the guise of fraud prevention is a new, horrifying attack vector for users of SMS 2FA https://www.vice.com/...