Delegate the Task /news

Real caseΒ· 2026

An AI password-reset flow let attackers hijack 20,000+ accounts

What happened

At least 20,225 Instagram accounts were compromised through an AI-chatbot password-reset path that failed to verify the requester owned the email. The company framed it as a separate-code-path bug; commenters called it a basic missing test. Good material to build β€” and fact-check β€” an article around.

β†—

What AI property explains this outcome? What would you do differently if you were the designer?

Read the source β†—