Pokémon's official X account was briefly compromised, with an unauthorised post promoting a memecoin disguised as a 30th anniversary celebration. The company has now responded and removed the content, but questions remain about the incident
Pokémon's official X account was briefly hijacked by an unknown party, resulting in a misleading post that promoted a cryptocurrency under the guise of an anniversary event. The incident, which took place on 17 August 2026 at around 3 PM Pacific Time, saw the account publish a message advertising a so-called "official Pokémon memecoin" and linking to a site styled to resemble a legitimate Pokémon 30th anniversary page.
Details of the Account Compromise
The fraudulent post was crafted to appear as an authentic Pokémon announcement, encouraging users to "celebrate 30 years of Pokémon" by joining a global trainer community through the $POKEMON memecoin. The link directed users to a website that mimicked official branding, increasing the risk of confusion. The post remained live for approximately thirty minutes before being deleted, during which time community notes and warnings began to appear beneath it, flagging the content as potentially deceptive.
Pokémon's social team responded shortly after the removal, confirming that the account had been accessed without authorisation and used to promote cryptocurrency. The company stated that the offending posts were not created or approved by Pokémon, had been removed, and that the account had since been secured. An investigation into the breach is ongoing, with Pokémon apologising for any confusion caused.
Community Reaction and Follow-Up
Following the official response, the comments section was quickly filled with relief and humour, with many referencing Team Rocket as the likely culprit in jest. However, the statement itself was also deleted not long after publication, and no further updates have been issued on the account regarding the hack. At this stage, it is unclear whether any users were directly affected by the scam link or if any sensitive information was compromised.
This is not the first time Pokémon has faced digital security challenges. In late 2024, a major breach at GameFreak led to the leak of hundreds of gigabytes of internal data, including concept art, prototypes, and source code. The following year, hackers released files from Pokémon Legends: Z-A, including early gameplay footage and cut content. While the latest incident did not result in a comparable data leak, it highlights the ongoing risks associated with high-profile gaming accounts.
Industry Context and Broader Risks
The Pokémon account hack is part of a wider trend of social-media compromises targeting gaming brands and communities. Cryptocurrency scams have become increasingly common, with attackers often leveraging trusted profiles to lend credibility to fraudulent schemes. Notably, the individual behind the recent Grand Theft Auto 6 leaks was also linked to a crypto promotion, underlining the crossover between high-profile leaks and digital scams in the gaming sector.
Pokémon's swift removal of the post and public acknowledgement of the breach are in line with best practices for incident response, but the deletion of the follow-up statement leaves some uncertainty about the full scope of the compromise. No evidence has yet emerged of lasting damage, but the situation remains under review.
What Remains Unclear
At present, Pokémon has not provided further details on how the account was accessed or whether any additional security measures will be implemented. The company has not confirmed if any user data was exposed or if the scam link resulted in financial loss for followers. The lack of a persistent public statement means players and fans are left waiting for more comprehensive information about the breach and its aftermath.
As with previous incidents involving major gaming brands, the episode serves as a reminder of the importance of robust account security and the risks posed by increasingly sophisticated social engineering tactics. Until more details are released, players are advised to remain cautious of unexpected promotions, even from official channels.
Account security on social platforms is a critical concern for both players and publishers. High-profile accounts are frequent targets for phishing, credential theft, and social engineering, as attackers seek to exploit trust for financial gain. Two-factor authentication, strong password management, and rapid incident response are essential defences, but even these measures cannot eliminate all risk. For players, vigilance remains key-especially when posts appear out of character or promote unfamiliar products.