GoPlus Security 🚦 engagement report
@GoPlusSecurity - 439K followers on X
Measured over 21 original posts from a 30-day window, last computed on August 30, 2026.
Engagement
A typical post picks up 44 interactions against 439K followers, an engagement rate of 0.01%. Measured over 21 original posts, its engagement rate beats 31% of 3,758 tracked accounts of a similar size, which puts it in the middle of its size range rather than at either end. Posts are seen about 11K times each, and 0.399% of those impressions turn into an interaction. That is about 2.51% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 1.5 posts a day over the last 30 days, with activity on roughly 77% of days. Most posts go out around 13:00 UTC, and Tuesday is the busiest day of the week. Of the 21 posts sampled, 71% carry an image or video and 67% link out. The account's strongest tracked post pulled 1.9K interactions, about 43x its own typical post. Recurring topics include #btc, #agentos, #base.
Measured over 21 original posts from a 30-day window, last computed on August 30, 2026. Recurring tags: #btc, #agentos, #base.
Compared with accounts its own size
GoPlus Security 🚦's engagement rate beats 31% of the tracked X accounts closest to it in follower count (3,758 accounts, accounts of similar size (decile 7 of 10)). A percentile is spread evenly by construction, so 50 really is the middle of that group and 90 really is its top tenth.
On engagement per impression rather than per follower it beats 28% of the same group. When those two numbers disagree, the gap is about how far its posts travel rather than how people react to them.
Where this sits in the catalog
At 0.01%, GoPlus Security 🚦 sits above the 10th percentile of the 36,521 accounts in this comparison. That places it in the bottom 25% band, which runs below 0.012%.
Show the percentile table
| Percentile | Engagement rate |
|---|---|
| 10th percentile | 0.002% |
| 25th percentile | 0.012% |
| 50th percentile | 0.08% |
| 75th percentile | 0.434% |
| 90th percentile | 2.10% |
| 99th percentile | 160.7% |
This ruler is the whole measured catalog, not a size-matched group: it shows where the raw rate falls across every account we can measure, all of which are large. For a like-for-like comparison, read the size-band percentile above instead. See how the bands are built
Posting timing
This account posts most often around 13:00 UTC, and Tuesday is its busiest day of the week. The bars below are the catalog-wide pattern, with this account's own busiest slot marked. They do not show how this account performs at each hour: we keep one aggregate per account, not one per hour, so that measurement does not exist in our data.
Show engagement by hour posted, utc as a table
| Hour (UTC) | Vs author median | Posts |
|---|---|---|
| 00:00 UTC | -1% | 50K |
| 01:00 UTC | -2% | 51K |
| 02:00 UTC | -3% | 50K |
| 03:00 UTC | -4% | 53K |
| 04:00 UTC | -6% | 43K |
| 05:00 UTC | -4% | 42K |
| 06:00 UTC | -4% | 48K |
| 07:00 UTC | -5% | 52K |
| 08:00 UTC | -4% | 60K |
| 09:00 UTC | -3% | 69K |
| 10:00 UTC | -2% | 72K |
| 11:00 UTC | -3% | 78K |
| 12:00 UTC | -2% | 86K |
| 13:00 UTC | -2% | 94K |
| 14:00 UTC | -4% | 97K |
| 15:00 UTC | -2% | 100K |
| 16:00 UTC | -3% | 97K |
| 17:00 UTC | -2% | 90K |
| 18:00 UTC | -1% | 84K |
| 19:00 UTC | -2% | 79K |
| 20:00 UTC | -1% | 74K |
| 21:00 UTC | -1% | 66K |
| 22:00 UTC | -2% | 57K |
| 23:00 UTC | -2% | 51K |
Show engagement by day of week as a table
| Day | Vs author median | Posts |
|---|---|---|
| Sunday | +4% | 230K |
| Monday | 0% | 286K |
| Tuesday | -2% | 276K |
| Wednesday | -1% | 251K |
| Thursday | -1% | 244K |
| Friday | -3% | 252K |
| Saturday | +3% | 227K |
Best tweets
- Aug 28, 202643x their median
UPDATE: All affected card balances will be refunded in full Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed. Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control. When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected. Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected. Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances. Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely. Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.
- Jul 31, 202629x their median
More than $38M has been stolen due to a Coldcard wallet vulnerability.⚠️ Funds from around 500 wallets were transferred to wallet bc1qnk, totaling 594.48 $BTC ($38.2M). Stay safe. https://t.co/gUmUfQLvdb https://t.co/Bg2XS39mWh https://t.co/XTmDa6lnev
- Aug 6, 202613x their median
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
- Aug 25, 202613x their median
Last night, the https://t.co/fw5Q0Q8IwZ webapp fell victim to an attack. Access to the platform has been halted, and no more funds are moving in or out of user wallets. This report, created by an independent community member, provides a detailed summary of the event: https://t.co/cGRPcn8Uuh. The team is working on a recovery plan and verification of the incident details. Please do not purchase $RIO on Algorand or Stellar; the bridges to these chains will remain closed indefinitely. Freehold and Districts are not impacted by this. Please do not use the https://t.co/fw5Q0Q8IwZ webapp anymore; Freehold is the only wallet we are actively maintaining going forward. We have identified deposits by the attacker into both @MEXC and @kucoincom and are in contact with them. The market impact on $RIO was limited, and the attacker was not able to sell much before everything was frozen. We believe CEXs can safely begin enabling deposits/withdrawals on BNB Chain again. We will work with law enforcement to identify the attacker.
- Aug 21, 202611x their median
I have just made the biggest mistake of my life I sent 429710 cate (my life savings) to what i believed was my new wallet address on fomo Being an idiot i typed it out very carefully or so i thought to my new sol address Bzj4TU2MdQ3gkkgm5t93ruzFEzLk7qRsuYJCq4jvMDeF Unfortunately for me i sent it to Bzj4tu2MdQ3gkkgm5t93ruzFEzLK7qRsuYJCq4jvMDeF and not Bzj4TU2MdQ3gkkgm5t93ruzFEzLk7qRsuYJCq4jvMDeF (I capitalized the TU cause im braindead)
- Aug 12, 20266.5x their median
An unknown victim was just drained of $25.6M in assets. The attacker swapped all the assets, including WBTC, cbBTC, LDO, USDS, and CRV, for DAI and ETH. Interestingly, the same wallet was drained of $24.23M in September 2023 due to malicious token approvals. The attacker eventually returned approximately 90% of the stolen funds. Theft address: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae Stay Smart.
- Aug 27, 20266.1x their median
We are aware of an issue affecting the MAMO Core Market on Base and are actively investigating. As a precaution, borrow caps for all Core Markets on Base have been set to 1 wei, preventing new borrowing and limiting the potential for further impact. The supply caps for MAMO and WELL have also been set to 1 wei. All other supply caps remain unchanged. We will share another update as soon as we have more information.
- Aug 25, 20262.0x their median
⚠️Exploit Breakdown: Cosmos EVM exploits hit in rapid succession, draining $17M+ Between Aug 20–23, a cluster of bugs involving the staking precompile + vesting accounts in cosmos/evm got weaponized. Three chains fell in three days: MANTRA, TAC, and KiiChain. Nominal losses >$17M. (Note: This is not the same as ASA-2026-002 from Jan 2026 — the ICS20 nested execution issue that cost Saga EVM ~$7M. Different code paths, different exploit methods, different patches. Some media mixed them up. Bad analysis.) Full breakdown in the thread 🧵
- Aug 7, 20261.6x their median
GoPlus Security is proud to support Robinhood Chain by @RobinhoodCrypto . As a Web3 security infrastructure provider, GoPlus brings its token and transaction risk detection capabilities to the Robinhood Chain ecosystem. GoPlus token and transaction risk detection for Robinhood Chain assets are now available across @GeckoTerminal , @DEXToolsApp , @dexscreener , @CoinMarketCap , @BinanceWallet , @wallet , @BitgetWallet , @TokenPocket_TP , @Debot_Official , and @UseUniversalX . To support builders and developers in the Robinhood Chain ecosystem, simply sign up on our platform to get your API key and access complimentary API quota for our services. Get started: https://t.co/Xx2ye7eJJs
- Aug 24, 2026
1/ 5 ⚠️Exploit Breakdown: The Term Labs governance attack Aug 23, @term_labs got absolutely rekt in a gov attack — ~$8.5M drained. Root cause? Voting power was paper-thin. Attacker bought absolute control with just 0.5 ETH. Here’s how it went down: Attacker swapped ~0.5 ETH → 0.485 tmvETH https://t.co/100XpiJQ9C
Ranked by total interactions across everything we have tracked for this account, which is a longer history than the 30-day window the rates above use. The multiple compares each post to this account's own median.
Recurring topics
The most frequent hashtags in the sampled posts. They describe what this account writes about; they are not a performance signal, and the catalog-wide breakdown on the hub shows how little hashtag count moves.
Buy or sell X accounts - escrow-protected
PlayerSells is an escrow marketplace for X accounts. Every deal is protected, with no middleman risk.
Reading these numbers
A typical post picks up 44 interactions against 439K followers, an engagement rate of 0.01%. Measured over 21 original posts, its engagement rate beats 31% of 3,758 tracked accounts of a similar size, which puts it in the middle of its size range rather than at either end. Posts are seen about 11K times each, and 0.399% of those impressions turn into an interaction. That is about 2.51% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 1.5 posts a day over the last 30 days, with activity on roughly 77% of days. Most posts go out around 13:00 UTC, and Tuesday is the busiest day of the week. Of the 21 posts sampled, 71% carry an image or video and 67% link out. The account's strongest tracked post pulled 1.9K interactions, about 43x its own typical post. Recurring topics include #btc, #agentos, #base.
- What is GoPlus Security 🚦's engagement rate on X?
- GoPlus Security 🚦 (@GoPlusSecurity) has an engagement rate of 0.01%, based on the median interactions across 21 original posts from the last 30 days against 439,193 followers. Replies, reposts and quote-posts of other people are excluded from that sample.
- Is that a good engagement rate?
- At 0.01%, GoPlus Security 🚦 sits above the 10th percentile of the 36,521 accounts in this comparison. Those comparison accounts are all large ones, because our scanning cadence is weighted towards big accounts, so this is a ranking among peers of similar scale rather than a ranking across X.
- Does @GoPlusSecurity have real engagement?
- Its engagement rate beats 31% of the tracked X accounts closest to it in follower count (3,758 accounts), which puts it in the middle of its size range group. Ranking inside a size band matters because engagement rate falls as accounts grow, so a raw rate would mostly re-measure the follower count. It is a starting point for a look at follower quality, not a verdict on it.
- When does @GoPlusSecurity post?
- Most posts go out around 13:00 UTC, and Tuesday is its busiest day, at roughly 1.47 posts per day across the measured window.