๐— ๐—ฒ๐˜๐—ฎ ๐—”๐—œ ๐—–๐—ต๐—ฎ๐˜๐—ฏ๐—ผ๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—™๐—น๐—ฎ๐˜„

Meta AI let attackers steal 20,000 Instagram accounts.

The flaw was simple. Attackers asked the chatbot to send password reset links to their own email addresses. The bot complied.

The attackers set new passwords and took over the accounts. They got DMs, profile data, and posts.

Only accounts without two-factor authentication (2FA) were at risk.

If you build AI agents, learn these lessons:

The danger is not the AI model. The danger is the glue code. Your identity checks must be strict.

Meta disabled the recovery flow. Affected users must reset passwords.

Source: https://dev.to/lymy1205/metas-ai-chatbot-just-became-a-password-reset-backdoor-for-20000-instagram-accounts-4kl9 Optional learning community: https://t.me/GyaanSetuAi