Nature of the Backend Flaw
Published 7/26/2026, 3:19:34 PM
X accounts utilizing passkey protection are currently vulnerable to a logic flaw in X's backend account management, which allows attackers to gain permanent control of an account if they achieve initial session access. While passkey technology itself remains cryptographically secure, X reportedly permits the registration of new passkeys without requiring explicit email confirmation, enabling attackers to "lock in" their access before a user can recover the account [Source: https://x.com/bjorn_hakansson/status/2081325521195999510].
Nature of the Backend Flaw
The vulnerability is not a breach of the passkey protocol but a failure in X's implementation of security checkpoints during account modification.
- No-Confirmation Registration: X allows a logged-in session to add a new passkey without sending a verification code or confirmation link to the registered email address [Source: https://x.com/bjorn_hakansson/status/2081325521195999510].
- Persistent Access: Once an attacker adds their own hardware-backed passkey, they possess a primary authentication method that persists even if the original user attempts a password reset.
- Recovery Bypass: Attackers typically follow the passkey addition by changing the account's email address. Because the attacker's passkey is already linked, they can bypass traditional recovery flows that rely on the original owner's credentials [Source: https://x.com/bjornhakanssonl/status/2081300964204503179].
Reported Risks and Impact
As of July 26, 2026, there is no official security advisory from X confirming a patch for this specific logic flaw [Note: not independently confirmed].
| Metric | Status / Detail | Source |
|---|---|---|
| Severity | High (Leads to permanent account loss) | [Source: https://x.com/bjorn_hakansson/status/2081325521195999510] |
| Exploitation | Active "hacking scams" reported in the wild | [Source: https://x.com/bjornhakanssonl/status/2081300964204503179] |
| Official Response | None (Support/Safety teams have not issued a fix) | [Source: https://x.com/bjorn_hakansson/status/2081325521195999510] |
| Re-enrollment Deadline | Nov 10 (Related to twitter.com to x.com migration) | [Source: https://currently.att.yahoo.com/att/x-lock-account-don-t-193256844.html] |
Domain Migration and Re-enrollment
Separate from the backend flaw, X has alerted users that they must re-enroll their passkeys by November 10 (originally cited for 2025, but relevant to ongoing domain transitions) due to the migration from twitter.com to x.com. Failure to re-enroll passkeys under the new domain may result in users being locked out of their accounts as the old credentials become invalid [Source: https://currently.att.yahoo.com/att/x-lock-account-don-t-193256844.html].
Recommendations for Affected Users
To mitigate the risk of this backend flaw, users should take the following manual steps:
- Audit Passkeys: Navigate to Settings > Security and account access > Security > Passkey and ensure no unrecognized keys are listed.
- Review Active Sessions: Regularly check "Sessions" to terminate any unauthorized or suspicious device logins immediately.
- Complete Migration: Ensure passkeys are updated to the
x.comdomain before the reported November 10 deadline to avoid service disruption [Source: https://currently.att.yahoo.com/att/x-lock-account-don-t-193256844.html].
While the cryptographic integrity of passkeys remains intact, the lack of backend verification at X makes the account recovery process the primary point of failure. Users remain vulnerable if an attacker gains even temporary access to an active session.