Limitless Podcast
Limitless Podcast

Hijacking Instagram: Behind The Massive AI Exploit

June 4, 2026

AI Summary

5 min read

In the time it took to describe a new kind of hack, the hack itself had already been completed on screen. Attackers weren't exploiting a bug in Meta's code. They were sweet-talking an AI assistant into handing over the password to a $200,000 Instagram handle. The result: accounts worth over $1 million were stolen, including the official White House account, which was compromised and began posting content it should not have. And technically, Meta's security systems worked exactly as designed.

The Confused Deputy: How the Exploit Worked

The attack relied on a concept the hosts call the "confused deputy." Imagine a night guard who holds the keys to every safety deposit box in a bank vault. The system is secure because the guard is the sole authority. But what if someone can walk up to that guard in the middle of the night and convince them—through pure conversation—that they are the rightful owner of a box? The guard, trying to be helpful, hands over the key. This is the new attack vector: social engineering directed not at a human, but at an AI.

Continue reading the full summary in the app — free to try.

Read Full Summary →

Free • No credit card required

What you'll learn

  • 1 (00:00) **The Discovery: AI as an Attack Vector** - Hackers exploit Meta's AI assistant to steal high-value Instagram handles, including the White House official account, by simply sweet-talking the bot into resetting passwords.
  • 2 (01:03) **How the AI Exploit Works** - The attacker uses a VPN to spoof the target's location, initiates a password reset, and convinces the AI assistant to send a recovery code to a new email.
  • 3 (02:53) **Three Methods of Exploitation** - The hosts detail the primary attack vector and two variations that bypass additional security.
  • 4 (06:46) **The Exploit Was Hiding in Plain Sight** - Users were openly discussing this vulnerability on Reddit for about a month before the White House account was hacked, acting as the alarm bell.
  • 5 (07:57) **The "Confused Deputy" Analogy** - This new attack vector shifts from exploiting code to using language to trick an AI, likened to a bank guard with keys who can be sweet-talked into opening a vault.
  • 6 (09:27) **Meta's Disappointing Response and Track Record** - The hosts criticize Meta's statement that "there was no breach of our systems," arguing this exploit is as bad as a traditional hack.
  • 7 (11:59) **A Bad Time for Meta** - The exploit comes amid massive layoffs, billions in losses, and low demand for their AI assistant, highlighting a lack of focus on security.

+ Full timestamped outline available in the app

Show Notes

A Meta AI account-recovery exploit let attackers trigger password reset links for Instagram and Facebook accounts through social engineering.

With this backdrop, we explore security risks for AI systems, including prompt injection, and close with advice on stronger authentication and safer account practices.

------
🌌 LIMITLESS HQ ⬇️

NEWSLETTER:    https://limitlessft.substack.com/
FOLLOW ON X:   https://x.com/LimitlessFT
SPOTIFY:             https://open.spotify.com/show/5oV29YUL8AzzwXkxEXlRMQ
APPLE:                 https://podcasts.apple.com/us/podcast/limitless-podcast/id1813210890
RSS FEED:           https://limitlessft.substack.com/

------
TIMESTAMPS

0:00 Meta AI Hack
2:35 How The Scam Worked
5:11 Two-Factor Fails
7:57 The Confused Deputy
9:30 Meta’s Security Failure
13:18 White House Response
17:32 How To Protect Yourself
22:14 Bigger AI Threats
23:55 Closing Thoughts

------
RESOURCES

Josh: https://x.com/JoshKale

Ejaaz: https://x.com/cryptopunk7213

------
Not financial or tax advice. See our investment disclosures here:
https://www.bankless.com/disclosures⁠

Limitless Podcast

More from this podcast

Limitless Podcast →