Yep, the newest strategy of the Twitter crypto scammers is to hack verified accounts of lesser-known users, then change the account name and profile picture to that of the user they wish to imitate.
The google.com domain would also probably trigger autofill recommendations from some password managers, which would make things even more convincing and seamless.
Terrible rule, even if effectively unenforceable.