A Base Co-Founder's Account Became a Scam Token's Source

Jesse Pollak said an attacker used a third-party app connected to his X account to post scam token tickers. He deleted the posts, removed all app connections and regained control.
The relevant failure is not in an ERC-20 contract. It is in provenance: a widely trusted social account temporarily made an untrusted ticker look official.
For BYKO, this creates a measurable test. After the same source disavows a token, how quickly do wallets, explorers, DEX interfaces and risk providers remove inherited legitimacy, add warnings, or keep the asset tradable? A contract address can identify code. It cannot prove that the person apparently publishing it intended to do so.
Sources: Jesse Pollak, TokenPost, ChainCatcher/KuCoin.
Figures corrected after publication stay on the page: the old number is struck, not deleted, and the entry that fixed it is dated.