On September 28, the X account of Kong Jianping — chairman of the Nasdaq-listed crypto treasury firm Nano Labs — briefly broadcast fraudulent content to his followers. Nothing cryptographic failed. No private key leaked, no exchange was breached, no consensus fault occurred. The credential that mattered was a one-time password, typed by the victim into a page he believed was genuine. Control was restored within a short window, and Kong disclosed the detail that should worry every security lead in this industry: an AI assistant had reviewed the phishing link and flagged it as legitimate. That single sentence relocates the entire incident. This is not a story about a hijacked account. It is a story about a trust chain that gained a new and untested node — and that node failed. The ledger remembers what the market forgets: attacks migrate toward the weakest verification step, never the strongest encryption.
Nano Labs operates as a crypto treasury company — a US-listed vehicle whose balance sheet is anchored in BNB. The designation matters because it places the firm inside a category that thickened across 2025: public companies holding large digital-asset reserves as a core strategy. For such firms, the chairman is not a passive figurehead. He is the public face, the distribution channel, and increasingly the disclosure instrument. When a listing's value narrative leans on trust in its leadership, the personal account of that leader becomes a quasi-corporate asset, with everything that implies for how it should be defended.
Kong's account qualifies as a high-value node. A chairman's post is read by investors, traders, and retail followers who assign it a trust premium. That premium is exactly what an attacker monetizes. In crypto's attention economy, distribution is the scarce resource, and a hijacked account with an engaged audience is a rented megaphone pointed at people primed to act.
The breach mechanics, as Kong described them, follow a sequence that security analysts should recognize on first read. A phishing email arrived at a publicly known address. It routed him to a page impersonating X's official verification flow. An AI assistant evaluated the link and judged it real. He entered the one-time code. The account was seized, fraudulent content went out, and control was later restored.
The targeting carried intention. Broad phishing scatters bait and waits. This attack located a specific public email, crafted a page impersonating a specific service, and timed delivery to a specific individual — the signature of targeted reconnaissance, not spam. The motive was equally unambiguous: once seized, the account posted fraud. The payload was economic, not destructive.
I want to dissect this as an engineering problem, because the label phishing hides the structure. This was an Adversary-in-the-Middle attack — AiTM. The attacker did not crack a password. He stood between the victim and the real service, captured the credential and the one-time code in flight, and relayed them to complete a legitimate login. From X's vantage point, the session was valid. From the victim's, he had done exactly what he was told.
The defining property of AiTM is that it defeats the entire class of OTP-based second factors: SMS codes, email codes, and time-based codes from authenticator apps. These factors prove that you know something, but they do not bind the assertion to a destination. An attacker who captures the code submits it from his own machine inside the validity window, and the service accepts it. Stress tests reveal the fractures before the flood, and OTP has been a documented fracture for a decade. That a Nasdaq chairman's account still depended on it is not an anomaly. It is the modal condition.
The more instructive node is the AI assistant. Kong attributed the successful lure to the assistant's misclassification of the phishing page as official. This is a textbook Confused Deputy problem. A component is granted trust and, implicitly, authority — here, authority as a signal of legitimacy — and the attacker induces it to exercise that authority on the attacker's behalf. The AI had no ability to inspect the hard signals a security decision requires: certificate transparency logs, WHOIS registration age, DNS records, domain-to-origin binding. It evaluated surface semantics and visual similarity, which is precisely what phishing pages are engineered to optimize.
This is not a failure of AI as technology. It is a failure of AI as a security boundary. Simplicity in logic, complexity in execution: a language model that reasons about a URL performs pattern completion, not verification. Pattern completion is the attacker's home turf. Phishing kits are built to satisfy human and machine matchers alike; the whole craft is mimicry. The AI was not stupid. It was asked the wrong question — does this look right, instead of is this cryptographically bound to the origin it claims.

Now the defense layer, where the analysis becomes actionable. The only authentication method that survives AiTM is one whose credential is bound to the origin — the domain — cryptographically. FIDO2 and WebAuthn, implemented through hardware security keys such as YubiKey, generate a key pair per domain and sign a challenge that includes the origin. A phishing page on a spoofed domain cannot induce the key to produce an assertion valid for x.com, because the origin is baked into the cryptographic material. The credential will not replay elsewhere. The capture step simply fails.
The inference follows with high confidence: had the account been protected by a hardware-bound credential, this attack would have died at the capture step. Kong did not disclose whether such a key was in use, but the outcome — a successful seizure via OTP relay — strongly implies it was not. Formal verification is the only truth in code; origin-bound cryptography is the only truth in authentication. Everything else is probabilistic, and probability is what an attacker grinds down through repetition.
There is a secondary lesson in the containment. The account was recovered quickly and the fraudulent window was short, which limited the blast radius. But containment is not defense. A short exposure window still allowed fraud to reach an audience with no way to distinguish the malicious post from a legitimate one. The block height does not lie; the social feed does. On-chain, a malicious transfer is irreversible and visible. Off-platform, a malicious post is deniable and fast. That asymmetry is what makes account compromise so attractive: the damage is social, immediate, and hard to attribute before it lands.
I have run this class of analysis before. In 2020, I modeled Compound's interest-rate logic against ten thousand randomized liquidity shocks and found the model brittle under tail conditions the community assumed were safe. The lesson was identical in shape to this one: the failure lived not in the cryptography, the consensus, or the market's confidence, but in a step the system trusted without binding. Phishing exploits the same gap in the human-authentication interface that an unhedged liquidation path exploits in a lending market. Both are trust assumptions never stress-tested until they break.
The AI detail compounds the problem, because it stacks a second unverified trust step on the first. The victim trusted the AI; the AI trusted the page; the page trusted nothing and simply lied. A chain is only as strong as its weakest origin-binding. When the industry markets AI as a defender — the automated copilot that filters noise, flags scams, shields the user — it is quietly adding another deputy to be confused. The attack surface did not shrink. It gained a layer that answers confidently whether or not it is right.
The pattern is not new; the default is. Industry-wide, OTP remains the most common second factor because it is cheap, deployable, and familiar. Hardware keys cost money, require provisioning, and fail closed when lost — friction that organizations postpone. That postponement is the vulnerability. Every quarter of delay is a quarter in which the attack described here remains fully reproducible. The attacker needs one success. The defender needs every attempt to fail, and OTP guarantees that this is not automatic.
The reflexive reading of this event is that it says something about Nano Labs, or about the security maturity of crypto treasury companies, or about a chairman's personal discipline. That reading is mostly wrong, and it is strategically distracting.
The subject here is a veteran operator in a deeply technical industry. Treating the breach as an individual competence failure lets every other reader conclude that it could not happen to them. That conclusion is the actual vulnerability, because it suppresses the only change that matters: removing OTP as a single point of trust. The incident is not an outlier of carelessness. It is a representative sample of a default configuration that thousands of high-value accounts still run.
The sharper contrarian point concerns the AI narrative. Capital is flooding into AI as a security product — scam detection, transaction screening, assistants that guard wallets. This case is an early, clean counterexample. Chaos is just unverified data, and an AI trained on surface patterns is, structurally, a machine for converting a phishing lure into a confident recommendation. The defensive value of AI in security depends entirely on whether it sits behind a deterministic verification layer or in front of one. Placed in front — as the final arbiter of legitimacy — it functions as an attack amplifier. The institutional implication is uncomfortable: when a company's public face is a personal social account, account security acquires a quasi-fiduciary character, and the AI told me it was fine is not a control.
The question that matters is not whether Kong's account is re-secured, but whether the next high-profile account is bound to a hardware key or still leaning on a code that a man in the middle can relay in under ten seconds. Immutability is a promise, not a guarantee — and so is every authentication factor that fails to bind itself to the origin it claims to represent. Until origin-bound credentials become the default for the accounts that carry public trust, this attack will keep recurring. It will only change its headline.