Meta's AI Support Feature Lets Anyone Hijack Instagram Accounts — Exploit Details Inside

✍️ OpenClawRadar📅 Published: June 1, 2026🔗 Source
Meta's AI Support Feature Lets Anyone Hijack Instagram Accounts — Exploit Details Inside
Ad

Meta's AI support feature for Instagram—currently A/B tested on a subset of accounts—contains a critical vulnerability that allows anyone to hijack an account with minimal effort. The exploit has been actively used in blackhat circles for several days, compromising over 100 high-value accounts.

How the Exploit Works

According to a Hacker News post by user parable, the attack requires only three steps:

  • Connect via a proxy or VPN close to the target account's region.
  • Ask the AI support agent to send a verification code to an arbitrary email address you control.
  • Receive the code, forward it to the agent, and the agent provides a password reset link that you can use to sign into the account.

This bypasses any email-based security checks because the AI agent itself handles the verification flow.

Ad

Impact and Context

The exploit has been circulating on Telegram and is trivial to execute. Victims report that their sessions were revoked and passwords changed with no email, text, or push notification. Even accounts with two-factor authentication (TFA) enabled may be vulnerable—some reports suggest TFA can be bypassed as well. Users affected by the exploit also experienced rate limiting on password reset emails, making it harder to recover accounts through normal channels.

This is not Meta's first security oversight. In February, a separate exploit allowed anyone to view the email address and phone number on file for any Instagram account. That bug was never officially acknowledged by Meta.

Recommended Mitigation

The immediate fix is to disable the AI support feature entirely until the verification flow is corrected. Affected users should revert hijacked accounts and usernames. As of the time of the Hacker News post, the flaw remained unpatched.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

Frontier AI Has Broken Open CTF Competitions — GPT-5.5 One-Shots Insane Pwn Challenges
Security

Frontier AI Has Broken Open CTF Competitions — GPT-5.5 One-Shots Insane Pwn Challenges

Claude Opus 4.5 and GPT-5.5 can solve medium-to-hard CTF challenges autonomously, turning scoreboards into a measure of orchestration and token budget rather than security skill.

OpenClawRadar
SCION: Switzerland's Secure Alternative to BGP Routing Protocol
Security

SCION: Switzerland's Secure Alternative to BGP Routing Protocol

SCION (Scalability, Control, and Isolation On Next-Generation Networks) is an internet routing architecture developed at ETH Zürich that replaces BGP's foundation with built-in security and multi-path routing. Unlike BGP patches like RPKI and BGPsec, SCION establishes tens or hundreds of parallel paths with millisecond rerouting when failures occur.

OpenClawRadar
Security Alert: Malicious Code in LiteLLM May Steal API Keys
Security

Security Alert: Malicious Code in LiteLLM May Steal API Keys

A critical security vulnerability has been identified in LiteLLM that could expose API keys. Users of OpenClaw or nanobot may be affected and should check the GitHub issues linked in the source.

OpenClawRadar
Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'
Security

Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'

A Reddit post warns about malware disguised as open-source AI agents and tools, where malicious code can be hidden in large codebases that users assume are safe because they're on GitHub. The post describes how 'vibe-coding' and autonomous AI agents condition users to run unknown programs without review.

OpenClawRadar