Then it hit me. I wrote an app with the Twitter API a few years ago (circa 2016). I checked and low and behold, this app still had an API permissions granted.
This is the first time leaving secrets in an old repo has bitten me. Serves me right for not setting up secret scanning. Glad to see Github has something so other people can't make the same mistake I did.
Interesting thing happened today. I saw tweets appearing on my account and wondered if I could have been hacked. My password was > 30 characters and using the full character set (alphanumeric + special) so this was unlikely.
@coffeeworks@Aresinger
I sold it after less than 30 minutes. $GALA and $SAND gave me nice entry points this morning. Couldn't resist 😉. My $650 are close to a $1,000 now. Fun times 🚩
#RecvProfit