Bankrbot deployer claims X platform has a critical authentication vulnerability or insider threat after attackers retained account access despite passkey protection.
Regulation & Gov ·
The deployer of Bankrbot alleged that X experienced either a critical backend authentication vulnerability or an insider threat after attackers maintained full account access despite the account being protected by a passkey, one of the more secure two-factor authentication methods. The attacker retained the ability to sign in and post malicious links even after the legitimate account holder was locked out by a suspension screen, while the account owner encountered 503 service unavailable errors from the X API—a discrepancy the deployer highlighted as inconsistent with a complete account lockdown.
The incident reflects a pattern of recent high-profile account compromises on X, including takeovers of the Robinhood CEO's account and the SpaceX account, both reportedly secured with multifactor authentication. The timing and scope of these breaches raise questions about whether a systemic vulnerability exists in X's authentication infrastructure or whether unauthorized internal access played a role.
What remains unclear is whether X has publicly acknowledged the incident, what technical investigation the platform has undertaken, or whether the specific vulnerability mechanism—if it exists—has been identified or remediated. The deployer's framing as an either-or proposition between a backend flaw and an inside job also leaves the root cause unconfirmed.