Calendly post-booking redirect and X app auth flow enabled a sophisticated account takeover

floguo · x · 2026-09-12

Entrepreneur Josh Wolk published a detailed post-mortem of how phishers hacked his account, urging Calendly and X to fix two design vulnerabilities:

Suggested fixes: Calendly should remove external post-booking redirects immediately (a dark pattern and major attack vector); X should display the real app name, permissions, and verified creator in the auth flow. He also warns that the impostor account @jigcompute is not him.

Original post →

More from Safety

Safety channel →