Just found a new account takeover attack on
@X. Here's what to look out for: First you get a DM from someone claiming to be reporter that is interested to write an article about you. Flattering! Bluecheck account that is several years old, a bunch of tweets... seems legit right? They send a scheduling link to chat with their team. The link says Google Calendar, but it actually redirects to an OAuth consent page for a X app. This appears to be an official "Google Calendar" app, showing an icon and correct URL. But look closely at the permissions it's asking for: full account access. If you click "Authorize app" you have now given this random app full access to everything on your X account. If you do approve this, the app redirects to a real calendly page and let's you schedule an event. The invite eventually comes via a throwaway email address. I'm guessing most people never notice. If you later go look at your connected apps in X, this "Google Calendar" app seems legit. There's no way to see the name of the developer, any verified domain, or what API requests the app has done. It silently has full control of your account. Hopefully someone from
@xdeveloperscan get this fixed
@elonmusk. Easy fix is to string match common names "Google" and also compare icons to popular apps to detect impersonation. The long-term solution is to build verification and trust for apps built on X. This will become even more important with AI systems and new features like calling and sending money. Please share this post so other folks don't get hit with the attack. And review/revoke any dubious apps you may have authorized. Stay safe!