AI agent tool Bankr developer deployer said the company’s X account intrusion may involve either a serious undiscovered security flaw in X’s backend systems or internal personnel. According to Odaily, deployer said Bankr had enabled passkeys, but when the team tried to log in, it was redirected to a suspended-account appeal page.

Deployer said the attacker was still able to log in and post malicious links after the team lost access to the account. The team also began receiving 503 errors from the X API, while the attacker continued posting normally. Deployer questioned why the team was restricted while the attacker retained full access.

Deployer also said several high-profile X accounts, including those of Robinhood CEO and SpaceX’s official account, were recently taken over, and some were reportedly using MFA. He called on the X team to investigate and explain the incidents.