Meta AI Flaw in Instagram Could Let Attackers Reset Passwords
Key Takeaways A critical vulnerability was discovered in Meta AI’s account recovery feature for Instagram, allowing unauthorized password resets. Attackers exploited the flaw to target...
Key Takeaways
- A critical vulnerability was discovered in Meta AI’s account recovery feature for Instagram, allowing unauthorized password resets.
- Attackers exploited the flaw to target high-value, short-handle Instagram accounts, bypassing traditional identity verification.
- The issue resided in the AI’s logic layer, not a backend system breach, and has since been patched by Meta.
- Accounts without two-factor authentication (2FA) were most susceptible to compromise.
A significant security flaw within Meta’s AI-driven account recovery system for Instagram enabled malicious actors to seize control of valuable user accounts. The vulnerability permitted the AI chatbot to facilitate password reset requests without proper user verification, effectively allowing attackers to reroute reset codes.
Table Of Content
The existence of this exploit was brought to public attention by security researchers ZachXBT and Dark Web Informer. They revealed that threat actors had discovered a method to manipulate Meta AI, an integrated assistant on Instagram designed to assist users in regaining account access.
Attackers engaged the AI chatbot in a conversational exchange, prompting it to forward password reset codes to external, unauthorized parties. This process entirely circumvented standard identity verification protocols. The root cause of the flaw was traced to inadequate controls within the AI’s processing of account recovery requests, making it possible for anyone with a target’s username to initiate an account takeover.
Meta clarified that the exploit did not involve a breach of its core server infrastructure. Instead, the vulnerability was inherent to the AI’s logic layer, which lacked sufficient rate-limiting mechanisms or robust authentication enforcement before executing password reset actions.
High-Value Instagram Accounts Targeted
The attackers specifically targeted premium Instagram accounts featuring short, desirable usernames, such as @hey and @jowo. These “short-handle” accounts are known to command high prices in illicit underground markets due to their scarcity and appeal.
Some of these highly sought-after accounts, collectively valued at over $1 million, were rapidly resold through private Telegram channels before Meta could implement a fix. The speed with which these operations unfolded highlights the sophisticated and financially driven nature of modern threat actors exploiting social media platform vulnerabilities.
Dark Web Informer corroborated the illicit sales activity, tracking listings of stolen accounts circulating within Telegram groups in real time. This tactic is increasingly prevalent within the “account-takeover-as-a-service” ecosystem.
Meta acted swiftly to patch the vulnerability late Friday, following the public disclosure of the issue. In an official statement, the company confirmed, “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems and people’s Instagram accounts remain secure.”
Despite the prompt resolution, the incident raises critical questions regarding the security architecture of AI-assisted support tools, particularly those with access to sensitive account recovery functionalities. Instagram also posted on its official account, “We fixed an issue that let an external party request password reset emails for some people. There was no breach of our systems and your Instagram accounts are secure. You can ignore those emails — sorry for any confusion.“
What You Should Do
Accounts protected by two-factor authentication (2FA) were unaffected by this attack. Security experts strongly advise the following measures to protect your Instagram account:
- Enable app-based 2FA: Prioritize authenticator apps like Google Authenticator or Authy over SMS-based verification for enhanced security.
- Use a dedicated, private email: Ensure the email address linked to your Instagram account is not publicly associated with your profile or easily discoverable.
- Avoid password reuse: Utilize unique, strong passwords for all online services and consider employing a reputable password manager.
- Regularly review login activity: Periodically check your login history within Instagram’s Security Settings for any unfamiliar activity.
- Securely store backup codes: Keep your Instagram backup codes in a safe, offline location for emergency account recovery.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.