1. Cookie Theft Attack
Hackers use a method called "pass-the-cookie," which exploits browser session cookies. These cookies allow users to stay logged into an account without having to re-enter their password and second factor at each login. By stealing these cookies, hackers can impersonate the victim and access their account without needing credentials.
3. Channel Impersonation and Exploitation
Once the channel is compromised, hackers modify its name, profile picture, and sometimes delete all content. They then broadcast fraudulent streams (often using Elon Musk's image to promote fake cryptocurrency offers).
Typical example: hackers ask viewers to transfer their cryptocurrency to a given address, promising to double the received funds. These streams are often quickly blocked by YouTube, but the channel owner must then prove they were not responsible for this fraud.