Billionaires Elon Musk, Jeff Bezos and Bill Gates are among many prominent US figures targeted by hackers on Twitter in an apparent Bitcoin scam.
The official accounts of Barack Obama, Joe Biden and Kanye West also requested donations in the cryptocurrency.
“Everyone is asking me to give back,” a tweet from Mr Gates’ account said. “You send $1,000, I send you back $2,000.”
The US Senate Commerce committee has demanded Twitter brief it about the incident next week.
Twitter said it was a “co-ordinated” attack targeting its employees “with access to internal systems and tools”.
“We know they [the hackers] used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf,” the company said in a series of tweets.
It added that “significant steps” had been taken to limit access to such internal systems and tools while the company’s investigation was ongoing.
The firm has also blocked users from being able to tweet Bitcoin wallet addresses for the time being.
Meanwhile, Twitter chief executive Jack Dorsey tweeted: “Tough day for us at Twitter. We all feel terrible this happened.”
The UK’s National Cyber Security Centre said its officers had “reached out” to the tech firm.
“While this appears to be an attack on the company rather than individual users, we would urge people to treat requests for money or sensitive information on social media with extreme caution,” it added in a statement.
US politicians also have questions. Republican Senator Josh Hawley has written to the company asking if President Trump’s account had been vulnerable.
President Trump’s account was not compromised, the White House said. “The president will remain on Twitter. His account was secure and not jeopardised during these attacks,” a statement said.
The chair of the Senate Commerce committee has also been in contact with Twitter.
“It cannot be overstated how troubling this incident is, both in its effects and in the apparent failure of Twitter’s internal controls to prevent it,” Senator Roger Wicker wrote to the firm.
He added that the company must brief the committee’s staff about the hack no later than Thursday 23 July.
One cyber-security expert said that the breach could have been a lot worse in other circumstances.
“If you were to have this kind of incident take place in the middle of a crisis, where Twitter was being used to either communicate de-escalatory language or critical information to the public, and suddenly it’s putting out the wrong messages from several verified status accounts – that could be seriously destabilising,” Dr Alexi Drew from King’s College London told the BBC.
Twitter earlier had to take the extraordinary step of stopping many verified accounts marked with blue ticks from tweeting altogether.
Password reset requests were also being denied and some other “account functions” disabled.
By 20:30 EDT (00:30 GMT Thursday) users with verified account started to be able to send tweets again, but Twitter said it was still working on a fix.
Dmitri Alperovitch, who co-founded cyber-security company CrowdStrike, told Reuters news agency: “This appears to be the worst hack of a major social media platform yet.”
On the official account of Mr Musk, the Tesla and SpaceX chief appeared to offer to double any Bitcoin payment sent to the address of his digital wallet “for the next 30 minutes”.
“I’m feeling generous because of Covid-19,” the tweet added, along with a Bitcoin link address.
The tweets were deleted just minutes after they were first posted.
But as the first such tweet from Musk’s account was removed, another one appeared, then a third.
Others targeted included:
- the rapper Kanye West
- reality TV star Kim Kardashian West
- former US President Obama
- former US Vice-President Joe Biden, who is the current Democratic presidential candidate
- media billionaire Mike Bloomberg
- the ride-sharing app Uber
- the iPhone-maker Apple
The Biden campaign said Twitter had “locked down the account within a few minutes of the breach and removed the related tweet”.
A spokesman for Bill Gates told AP news agency: “This appears to be part of a larger issue that Twitter is facing.”
The BBC can report from a security source that a web address – cryptoforhealth.com – to which some hacked tweets directed users was registered by a cyber-attacker using the email address firstname.lastname@example.org.
The name “Anthony Elias” was used to register the website, but may be a pseudonym – it appears to be a play on “an alias”.
Cryptoforhealth is also a registered user name on Instagram, apparently set up contemporaneously to the hack.
- Twitter hack: What went wrong and why it matters
- The Benjamin Netanyahu Twitter hack that never was
- What is Bitcoin?
The description of the profile read “It was us”, alongside a slightly smiling face emoticon.
The Instagram profile also posted a message that said: “It was a charity attack. Your money will find its way to the right place.”
In any case, the real identities of the perpetrators are as yet unknown.