frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: X account hacked again – no email when attacker changed the email? How?

9•hadaoaxb•7mo ago
Hey folks, Hey everyone, I’m trying to figure out how this happened and hoping someone here might know more about how X’s (Twitter) system works.

First time, my company’s X account was hacked 2 weeks ago. Totally my fault — I clicked on a phishing email and gave them the password and even uploaded some company documents and my ID. But after 12hrs, X support helped me recover the account, I changed the password, enabled all 2FA options (eventhough I did it from the beginning but hacker bypassed it), and they told me they revoked all sessions. Since then, I’ve only been logging in from the official mobile app and all other staff only got delegated, not login access.

Second time, 2 weeks later (yesterday)— I suddenly get kicked out of the app, all my team delegator members lose access too, and when I try to log back in, it says it can’t find my email. . But this time, I never got any notification from X saying the email was changed like the first time.

My email is totally secure — no sign of compromise, no new login sessions.

SIM is fine. No new logins. I didn’t click on anything sketchy nor install any apps recently since that first phishing attack.

I’m wondering:

1. Can someone change the email on an X account without triggering a notification to the original email?

2. Does X suppress those if someone contacts support and claims the original email is compromised after 2 weeks?

Would love to hear if anyone else has seen something like this or knows how the backend systems work. I'm still waiting on X support, but this is really bothering me.

Comments

viraptor•7mo ago
Is there a chance that your email for owned as well and the notification has been filtered/deleted?
acheong08•7mo ago
My Twitter account was hacked recently as well. A seemingly impossible hack: randomly generated password stored in a self hosted password manager accessible only from my wireguard network. I log everything and no signs of access from an IP outside my normal range. The email is also self hosted with a randomly generated password stored on an external device (not password manager since email is more important).

I suspect a third party app has been compromised. https://help.x.com/en/managing-your-account/connect-or-revok...

Specifically, the only app authorized on my account was Twitcasting (https://en.m.wikipedia.org/wiki/TwitCasting).

The attacker seemed to have used it to add additional apps onto my account and control it without having my password.

scottydelta•7mo ago
Hey I have a pretty similar setup. Bitwarden/vaultwarden hosted behind wireguard and openvpn, 2 vpns to provide redendency.

It works very nicely for me. Although not having split tunnel was an issue for me on the wireguard Mac OS client but I hacked that by writing a custom client with a mix of bash script and xbar mac app.

KomoD•7mo ago
Authorizing an app won't let that app add more apps, at least as far as I know.
acheong08•7mo ago
I'd think so too but removing all the apps stopped my problems. Maybe a vuln with Twitter at some point. I can't think of any other way to hack an account I don't even use

KV Cache Transform Coding for Compact Storage in LLM Inference

https://arxiv.org/abs/2511.01815
1•walterbell•4m ago•0 comments

A quantitative, multimodal wearable bioelectronic device for stress assessment

https://www.nature.com/articles/s41467-025-67747-9
1•PaulHoule•6m ago•0 comments

Why Big Tech Is Throwing Cash into India in Quest for AI Supremacy

https://www.wsj.com/world/india/why-big-tech-is-throwing-cash-into-india-in-quest-for-ai-supremac...
1•saikatsg•6m ago•0 comments

How to shoot yourself in the foot – 2026 edition

https://github.com/aweussom/HowToShootYourselfInTheFoot
1•aweussom•6m ago•0 comments

Eight More Months of Agents

https://crawshaw.io/blog/eight-more-months-of-agents
3•archb•8m ago•0 comments

From Human Thought to Machine Coordination

https://www.psychologytoday.com/us/blog/the-digital-self/202602/from-human-thought-to-machine-coo...
1•walterbell•8m ago•0 comments

The new X API pricing must be a joke

https://developer.x.com/
1•danver0•9m ago•0 comments

Show HN: RMA Dashboard fast SAST results for monorepos (SARIF and triage)

https://rma-dashboard.bukhari-kibuka7.workers.dev/
1•bumahkib7•10m ago•0 comments

Show HN: Source code graphRAG for Java/Kotlin development based on jQAssistant

https://github.com/2015xli/jqassistant-graph-rag
1•artigent•15m ago•0 comments

Python Only Has One Real Competitor

https://mccue.dev/pages/2-6-26-python-competitor
3•dragandj•16m ago•0 comments

Tmux to Zellij (and Back)

https://www.mauriciopoppe.com/notes/tmux-to-zellij/
1•maurizzzio•17m ago•1 comments

Ask HN: How are you using specialized agents to accelerate your work?

1•otterley•18m ago•0 comments

Passing user_id through 6 services? OTel Baggage fixes this

https://signoz.io/blog/otel-baggage/
1•pranay01•19m ago•0 comments

DavMail Pop/IMAP/SMTP/Caldav/Carddav/LDAP Exchange Gateway

https://davmail.sourceforge.net/
1•todsacerdoti•20m ago•0 comments

Visual data modelling in the browser (open source)

https://github.com/sqlmodel/sqlmodel
1•Sean766•22m ago•0 comments

Show HN: Tharos – CLI to find and autofix security bugs using local LLMs

https://github.com/chinonsochikelue/tharos
1•fluantix•22m ago•0 comments

Oddly Simple GUI Programs

https://simonsafar.com/2024/win32_lights/
1•MaximilianEmel•23m ago•0 comments

The New Playbook for Leaders [pdf]

https://www.ibli.com/IBLI%20OnePagers%20The%20Plays%20Summarized.pdf
1•mooreds•23m ago•1 comments

Interactive Unboxing of J Dilla's Donuts

https://donuts20.vercel.app
1•sngahane•24m ago•0 comments

OneCourt helps blind and low-vision fans to track Super Bowl live

https://www.dezeen.com/2026/02/06/onecourt-tactile-device-super-bowl-blind-low-vision-fans/
1•gaws•26m ago•0 comments

Rudolf Vrba

https://en.wikipedia.org/wiki/Rudolf_Vrba
1•mooreds•27m ago•0 comments

Autism Incidence in Girls and Boys May Be Nearly Equal, Study Suggests

https://www.medpagetoday.com/neurology/autism/119747
1•paulpauper•27m ago•0 comments

Wellness Hotels Discovery Application

https://aurio.place/
1•cherrylinedev•28m ago•1 comments

NASA delays moon rocket launch by a month after fuel leaks during test

https://www.theguardian.com/science/2026/feb/03/nasa-delays-moon-rocket-launch-month-fuel-leaks-a...
1•mooreds•29m ago•0 comments

Sebastian Galiani on the Marginal Revolution

https://marginalrevolution.com/marginalrevolution/2026/02/sebastian-galiani-on-the-marginal-revol...
2•paulpauper•32m ago•0 comments

Ask HN: Are we at the point where software can improve itself?

1•ManuelKiessling•32m ago•2 comments

Binance Gives Trump Family's Crypto Firm a Leg Up

https://www.nytimes.com/2026/02/07/business/binance-trump-crypto.html
1•paulpauper•33m ago•1 comments

Reverse engineering Chinese 'shit-program' for absolute glory: R/ClaudeCode

https://old.reddit.com/r/ClaudeCode/comments/1qy5l0n/reverse_engineering_chinese_shitprogram_for/
1•edward•33m ago•0 comments

Indian Culture

https://indianculture.gov.in/
1•saikatsg•35m ago•0 comments

Show HN: Maravel-Framework 10.61 prevents circular dependency

https://marius-ciclistu.medium.com/maravel-framework-10-61-0-prevents-circular-dependency-cdb5d25...
1•marius-ciclistu•36m ago•0 comments