Bankr developer says X account breach may point to backend flaw or insider risk
Bankr developer deployer has again commented on the compromise of Bankr’s X account, arguing that the incident may indicate one of two possibilities: a serious undiscovered security flaw in X’s backend systems, or involvement by insiders. According to deployer, Bankr had already enabled Passkey protection, yet when the team tried to regain access, they were redirected to an appeal page for a suspended account. At the same time, the attacker was still able to log in and post malicious links even after the team had lost access. deployer also said the team began receiving 503 errors from the X API while the attacker continued posting normally. He questioned why the legitimate team was restricted while the attacker appeared to retain full permissions. The developer added that several other high-profile X accounts, including Robinhood CEO and the official SpaceX account, were reportedly taken over recently, with some of those accounts said to have had MFA enabled as well. He called on X to investigate the matter and explain what happened.

