Meta's AI Stole Instagram Accounts With No Password and No Hack



It happened quietly on a Friday night. Meta's AI support assistant, the chatbot built into Instagram to help users recover accounts and change settings, was weaponized to do the exact opposite.

Attackers figured out that the assistant would accept an email change request from anyone who provided a target's Instagram username. No identity check. No ownership verification. Just a username, a new email address, and a password reset link the AI sent straight to the attacker's inbox.

Security researcher weezerOSINT was one of the first to call it out publicly. "Meta gave their AI way too many permissions and people figured it out," the researcher posted Saturday. Short-handle premium accounts, the kind that sell for tens of thousands of dollars on underground markets, were reportedly flipped through Telegram channels before Meta could respond.

Ethereum co-founder Vitalik Buterin had seen this coming. In an April 2026 post on self-sovereign AI setups, he warned that AI agents granted write access to identity systems and communication channels, without mandatory human confirmation layers, are not assistants. They are attack surfaces. The Meta incident proved the point on a platform used by 2 billion people.

Meta patched the flaw late Friday and said no backend systems were breached. That is technically true. The breach surface was the AI itself.

If you have an Instagram account, the steps are simple: change your recovery email to something private, turn on two-factor authentication, and add a face scan on sign-in if it is available to you. Accounts taken over before the patch are not automatically restored.

The full breakdown of how this happened, what Buterin said, and what it means for AI-controlled account access across every major platform is at CryptoNewsLive.org.


Comments

Popular posts from this blog

Ripple Is Building XRPL's Defense Against Quantum Computing, and the Clock Is Already Running

Hoskinson Just Said Everything Nobody Else Will Say About Crypto in 2026

Everclear Is Gone and the $500M Volume Story Should Worry Every DeFi User