A Fake Tweet Just Erased $100 Billion for Three Minutes

A Fake Tweet Just Erased $100 Billion for Three Minutes

Tech News algorithms security stock market twitter

So I was half-watching my RSS reader around 1pm on Tuesday (yeah, still using one, more on that fight some other day) when Twitter did that thing where a totally normal timeline suddenly turns into everyone typing in all caps at once. The AP's account had tweeted that there'd been two explosions at the White House and that the President was hurt. Except it hadn't happened. Someone had broken into @AP and posted a hoax, and for about three minutes the stock market genuinely believed it.

The Dow dropped something like 140-something points almost instantly. Estimates I saw floating around put the vanished market value at over a hundred billion dollars, gone and then mostly back within minutes once it was clear the tweet was fake and the AP started scrambling to tell people its account was compromised. The Syrian Electronic Army took credit for it, which tracks, they'd been going after news orgs' social accounts for weeks at this point.

Here's the part that actually got under my skin though, and its not the hack itself. Accounts get phished, that happens, its almost boring at this point how often it happens. What bugged me is how obviously it proved that a meaningful chunk of the stock market is now just software reading tweets and pulling triggers with zero human in the loop for the first several seconds. Nobody at a trading desk read "Breaking: Two Explosions in the White House and Barack Obama is injured," thought about it, and decided to sell. A script saw the words "explosion" and "White House" near each other and dumped positions. That's not a hack story anymore, that's an infrastructure story, and its a genuinely alarming one if you think about it for more than ten seconds.

I don't work in finance and I'm not going to pretend I understand the full plumbing of high frequency trading. But I do know enough to say that building a system where a fake sentence from a compromised account with two million followers can erase and then instantly restore over a hundred billion dollars of paper value is a system with a pretty obviously broken input layer. The market recovered fast, sure. Cold comfort if you were the poor soul with a stop-loss order that triggered in that window and sold at the bottom of a hole that didn't exist thirty seconds later.

And this wasn't even the SEA's first swing this month. They'd already been in the BBC's weather Twitter account a few days earlier, tweeting nonsense there too, apparently as some kind of test run or just because they could. Feels like these guys have a whole shopping list of verified news accounts and they're just working down it one phishing email at a time. If you run social media for literally any newsroom right now and you're not on some kind of hardware token or app-based two-factor setup, I genuinely don't know what you're waiting for. Yes I know Twitter still doesn't really give you good options for that as of this week. That's a separate complaint and I've made it before and I'll make it again.

What I keep coming back to, honestly, is how casually everyone moved on. Market closed basically fine that day. AP got its account back, apologized, moved on. Everyone tweeted their jokes about it (there were a lot of "well that escalated quickly" variations, some genuinely funny, most not) and by dinner it was old news. But the actual lesson, that a huge chunk of the money moving through the largest financial market on earth reacts to unverified text strings faster than any human possibly could, just kind of sailed past most of the coverage I read. Everyone wanted to talk about who did it and whether the AP had good enough security. Almost nobody wanted to talk about why the market itself is built to be that gullible.

Not really sure there's a fix for that one that doesn't involve slowing the whole system down on purpose, which nobody with money at stake actually wants. So I guess we just wait for the next fake tweet.