frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: X account hacked again – no email when attacker changed the email? How?

9•hadaoaxb•3h ago
Hey folks, Hey everyone, I’m trying to figure out how this happened and hoping someone here might know more about how X’s (Twitter) system works.

First time, my company’s X account was hacked 2 weeks ago. Totally my fault — I clicked on a phishing email and gave them the password and even uploaded some company documents and my ID. But after 12hrs, X support helped me recover the account, I changed the password, enabled all 2FA options (eventhough I did it from the beginning but hacker bypassed it), and they told me they revoked all sessions. Since then, I’ve only been logging in from the official mobile app and all other staff only got delegated, not login access.

Second time, 2 weeks later (yesterday)— I suddenly get kicked out of the app, all my team delegator members lose access too, and when I try to log back in, it says it can’t find my email. . But this time, I never got any notification from X saying the email was changed like the first time.

My email is totally secure — no sign of compromise, no new login sessions.

SIM is fine. No new logins. I didn’t click on anything sketchy nor install any apps recently since that first phishing attack.

I’m wondering:

1. Can someone change the email on an X account without triggering a notification to the original email?

2. Does X suppress those if someone contacts support and claims the original email is compromised after 2 weeks?

Would love to hear if anyone else has seen something like this or knows how the backend systems work. I'm still waiting on X support, but this is really bothering me.

Comments

viraptor•1h ago
Is there a chance that your email for owned as well and the notification has been filtered/deleted?
acheong08•1h ago
My Twitter account was hacked recently as well. A seemingly impossible hack: randomly generated password stored in a self hosted password manager accessible only from my wireguard network. I log everything and no signs of access from an IP outside my normal range. The email is also self hosted with a randomly generated password stored on an external device (not password manager since email is more important).

I suspect a third party app has been compromised. https://help.x.com/en/managing-your-account/connect-or-revok...

Specifically, the only app authorized on my account was Twitcasting (https://en.m.wikipedia.org/wiki/TwitCasting).

The attacker seemed to have used it to add additional apps onto my account and control it without having my password.

scottydelta•26m ago
Hey I have a pretty similar setup. Bitwarden/vaultwarden hosted behind wireguard and openvpn, 2 vpns to provide redendency.

It works very nicely for me. Although not having split tunnel was an issue for me on the wireguard Mac OS client but I hacked that by writing a custom client with a mix of bash script and xbar mac app.

Show HN: Tree-hugger-JS: CSS selectors for JavaScript AST analysis and MCP

1•chw9e•1m ago•0 comments

AI sceptic Emily Bender: 'The emperor has no clothes'

https://www.ft.com/content/9029cc1c-4a3f-42ca-9939-f3ef8e8336ae
1•zahirbmirza•1m ago•2 comments

AI and the existential question about language

https://trace.yshui.dev/2025-06-ai-language.html
2•yshui•8m ago•0 comments

Drinks in glass bottles contain more microplastics than those in other container

https://www.anses.fr/en/content/drinks-glass-bottles-contain-more-microplastics-those-other-containers
2•Zealotux•12m ago•0 comments

Data driven home purchase community

https://www.realrealchat.com/
2•xcabel•13m ago•0 comments

From Bytes to Ideas: Language Modeling with Autoregressive U-Nets

https://arxiv.org/abs/2506.14761
3•Anon84•15m ago•0 comments

Exercise-induced CLCF1 attenuates age-related muscle and bone decline in mice

https://www.nature.com/articles/s41467-025-59959-w
2•gnabgib•15m ago•0 comments

MCP vs. A2A (In 6 Minutes)

https://supabase.manatee.work/storage/v1/object/public/videos/ede034cb-5de9-4057-839e-e93061f0f7c7.mp4
2•_josh_meyer_•22m ago•0 comments

They Trusted ChatGPT to Plan Their Hike – and Ended Up Calling for Rescue

https://thetrek.co/they-trusted-chatgpt-to-plan-their-hike-and-ended-up-calling-for-rescue/
3•speckx•23m ago•0 comments

BitVM3: Efficient Computation on Bitcoin [pdf]

https://bitvm.org/bitvm3.pdf
1•wslh•23m ago•0 comments

Study: Meta AI model can reproduce almost half of Harry Potter book

https://arstechnica.com/features/2025/06/study-metas-llama-3-1-can-recall-42-percent-of-the-first-harry-potter-book/
2•eyegor•24m ago•0 comments

Palantir: Profits, Power and the Kill Machine

https://citizensreunited.substack.com/p/inside-palantir-profits-power-and
2•terabytest•25m ago•0 comments

Akkurat Typeface

https://lineto.com/typefaces/akkurat/
1•handfuloflight•27m ago•0 comments

Show HN: Prpolish, a CLI that uses AI to write and review your GitHub PRs

https://github.com/yashg4509/prpolish
1•yashg4509•29m ago•0 comments

Washington State Patrol to Find Speeding Hot Spots Using Harvested Phone Data

https://www.roadandtrack.com/news/a65124453/washington-state-patrol-cell-phone-data-locate-speeding-hot-sport/
4•toss1•31m ago•0 comments

I built a fansite for "Grow a Garden" on Roblox – would love feedback

https://growagarden.com/
1•incendies•46m ago•1 comments

AbsenceBench: Language models can't tell what's missing

https://arxiv.org/abs/2506.11440
35•JnBrymn•46m ago•6 comments

Ask HN: What hobby would you like to try?

4•randerson001•46m ago•4 comments

Regulation with regard to energy labelling of smartphones and slate tablets

https://eprel.ec.europa.eu/screen/product/smartphonestablets20231669
3•aucisson_masque•54m ago•0 comments

Masa Son Pitches $1T US AI Hub to TSMC, Trump Team

https://www.bloomberg.com/news/articles/2025-06-20/masayoshi-son-s-next-bet-a-1-trillion-ai-robotics-hub-in-arizona
4•anythingworks•54m ago•0 comments

Dispelling Myths and Misinformation

https://matrix.org/blog/2025/06/dispelling-myths/
1•foresto•1h ago•0 comments

Tiny Teams Hall of Fame

https://tinyteams.xyz
1•akyuu•1h ago•0 comments

Pringles cans on drones: Ukraine's weapons ingenuity takes all forms

https://www.defensenews.com/global/europe/2025/06/20/pringles-cans-on-drones-ukraines-weapons-ingenuity-takes-all-forms/
2•giuliomagnifico•1h ago•0 comments

Building a Healthy Relationship with AI, a Cross-Disciplinary Perspective

http://nombiezinja.com/word-things/2025/6/18/building-a-healthy-relationship-with-ai-a-cross-disciplinary-perspective
1•xena•1h ago•0 comments

Has a nuke gone off?

https://www.hasanukegoneoff.com/
10•voxadam•1h ago•1 comments

Smartphone is a parasite, according to evolution

https://theconversation.com/your-smartphone-is-a-parasite-according-to-evolution-256795
7•Eldar_•1h ago•1 comments

The Parent Presentation | How to convince your parents to get you a Mac | Apple

https://www.youtube.com/watch?v=5O5U7hE65W0
2•miles•1h ago•0 comments

Avoid Workspaces (2014)

https://blog.z3bra.org/2014/11/avoid-workspaces.html
2•Bogdanp•1h ago•0 comments

Mozilla is killing its Pocket and Fakespot services to focus on Firefox

https://arstechnica.com/gadgets/2025/05/mozilla-is-killing-its-pocket-and-fakespot-services-to-focus-on-firefox/
5•markerz•1h ago•1 comments

Under shadow of Trump warning, Africa pioneers non-dollar payments systems

https://www.reuters.com/world/africa/under-shadow-trump-warning-africa-pioneers-non-dollar-payments-systems-2025-06-20/
4•nabla9•1h ago•0 comments