The official Pokémon account on X was compromised for about 30 minutes. In that window the hacker posted a link to a memecoin, using one of the most recognizable brands in entertainment as a billboard. The account has since been recovered and Pokémon has acknowledged the breach publicly.
Thirty minutes doesn’t sound like much. For this kind of scam it’s an eternity.
Why the target makes sense
Memecoin scams live or die on borrowed credibility. Nobody buys a token because a random wallet told them to. They buy because something they already trust appeared to endorse it, and because the window to act feels like it’s closing. A brand account with millions of followers, a verified badge, and decades of goodwill is the perfect delivery vehicle. The scammer isn’t selling a coin. They’re renting a reputation for half an hour.
Pokémon in particular skews young and skews trusting. Whoever did this understood the audience.
We’ve watched this play out enough times now that the pattern is boring: a big account goes quiet-weird, posts a contract address, the replies fill with people yelling “HACKED” while others quietly ape in, and 20 minutes later it’s gone. Sometimes the money is real. Usually the people holding the bag are the ones who thought they were early.
X’s part in this
The uncomfortable bit is how little the platform seems to slow any of this down. A verified corporate account suddenly posting a crypto contract link is about as clear an anomaly signal as exists. Nothing about a Pokémon account’s posting history resembles it. That should be a trivially detectable pattern, and yet accounts of this size keep getting taken over and keep getting a full half-hour of unimpeded reach before recovery kicks in.
Account recovery for large brands on X has been slower and murkier since the platform gutted much of its trust and safety operation. That’s not speculation about this specific incident, but it is the environment brands are operating in. The recovery process is a support ticket, and support tickets take time that a scam does not need much of.
What brands should actually do
Hardware security keys on every social account, not SMS 2FA. Aggressive audits of who has delegated access and which third-party apps still hold tokens from a campaign that ended in 2021. Most of these compromises are not exotic. They’re a phished contractor or a stale integration.
The frustrating part is that this costs almost nothing to prevent and enormous amounts to clean up. The Pokémon Company will be fine; the brand is bulletproof and the post is deleted. The people who clicked through and bought are not getting a statement.
Still unknown: how the account was accessed in the first place, and whether the token pulled in real money before the post came down.