Social Jacking: How I Hijacked Wim Hof’s Followers on Instagram

stabla
5 min readNov 2, 2020

In order to keep my own privacy, I have decided to hide my Instagram username. This story is relative to an event that happened during December, 2019.

Aldo Cruces

During Winter 2019, I was bored and was losing time on Instagram. I am a big fan of Wim Hof (https://www.instagram.com/iceman_hof/), so it makes sense why I followed him. If you don’t know who Wim Hof is, aka. Ice Man, don’t hesitate to check some hof its accomplishment (to quote Wikipedia page):

  • On 16 March 2000, Hof set the Guinness World Record for farthest swim under ice, with a distance of 57.5 metres
  • On 26 January 2007, Hof set a world record for fastest half marathon barefoot on ice and snow, with a time of 2 hours, 16 minutes, and 34 seconds
  • Hof has set the world record for longest time in direct, full-body contact with ice a total of 16 times
  • In 2007, Hof climbed to an altitude of 7,200 metres (23,600 ft) on Mount Everest wearing nothing but shorts and shoes, but failed to reach the summit due to a recurring foot injury
  • In February 2009, Hof reached the top of Mount Kilimanjaro within two days wearing only shorts and shoes , but he failed due to injury.
  • In September, he ran a full marathon in the Namib Desert without water

Long story short, this guy is cool and you have a lot to learn from him. If you have time, you should definitely view some videos about him. I’m not surprised at all about why he has 1.4 million followers on Insta in November 2020, but at the time I did the Hijack, he had 700k (which was already a lot!).

While I was scrolling instagram, I spotted a new post of Ice Man. I read the description and noticed that there was a strange account tagged in the description of the post.

It was @ zina_brownshaddow

Did you see that too? TWO “d”.

It could be perfectly normal, but in a doubt, I checked the account. And it was not that fine.

Account zina_brownshaddow doesn’t exist

In fact, the tagged account was not existing. Do you have the same idea as I had? I changed my username on instagram in order to impersonate @ zina_browshaddow

I have changed my @ on Instagram

I changed my profile picture as well, to be more credible. And because, my mind was turned on experimental mode, I was like “let’s try new things! Let’s see some statistics!”, I created — in a rush — an Amazon Associate account.

The new zina_brownshaddow account

Amazon Associates allows you to put URL, and get a tiny commission when the product is bought. I have decided to promote the book of Wim Hof with an associate link.

And now, what?

What happened?

Growth

To create some mystery about my account, I have decided to turn my account on private mode. In fact, I’m pretty sure that it created more mystery around zina_brownshaddow — people did not know if it was a real account or a fake.

During 1 whole week, I have not accepted anyone.

On the whole timeframe, I gained followers on a daily basis. It was pretty enjoyable to see it growing and see how many people I was driving on my account — or, let’s be more accurate, how many people Wim Hof was driving to my profile.

“ 10 Following requests”
“37 Following requests”
“220 Following requests”

I haven’t the last screen before accepting them all — but I remember that it drove me 700 new followers. From an account of 700k, I gained 700 followers.

Math are simple: 700 / 700000 = 0.001 = 0.1% of people wanted to follow me. It’s ridiculous, right? It’s not that much. It’s in fact nothing. Engagement rate is far better with paid ads. Yet it talks for itself, if you are able to hijack an account with 241m followers (as Cristiano Ronaldo https://www.instagram.com/cristiano), you can — in theory — make 240 000 new followers in less than a week (and for free).

It’s nothing incredible, and to be honest with you, I did not sell anything through the affiliate link… I was a bit sad about that. That’s life.

In the final run, this has no value at all, but it was really an interesting experience.

1 year later

One year later, I decide to make this funny trick public, even if some of you probably already know such thing.

Let’s be honest, such method will not drive you valuable followers and it is literally Hijacking. FYI, I have lost more than 60% of followers since this event. Yet, I wanted to show you the method, show you the “vulnerability” even if it’s not really one, it is more or less, abusing of somebody’s mistake.

Bonus

I have created an open source project (Python) that make it easier to check for a list of accounts if they have done mistakes in their previous posts. You are free to add your own accounts in the file account.txt and run the script to see. You are also free to improve or modify the script!

See Socijack on Github:

Let’s try it together. I logged into my own Instagram account, created a post, added a random username in the description of a post: @ 183kdk (this username is not taken on Instagram).

Then, I ran the script:

We can see that the account @ 183kdk has been detected and is available!

If you have trouble with this project, don’t hesitate to contact me on Twitter or leave a message under this article, I will take time to answer!

--

--