Calendly post-booking redirect and X app auth flow enabled a sophisticated account takeover
floguo · x · 2026-09-12
Entrepreneur Josh Wolk published a detailed post-mortem of how phishers hacked his account, urging Calendly and X to fix two design vulnerabilities:
- The phisher sent a genuine Calendly link; after submitting his name, Calendly allowed an auto-redirect to any link without disclosure.
- The redirect landed on an unlabeled X app auth flow that, on mobile, looked like a required Calendly form step.
- It actually granted a "guest manager" app broad account permissions, enabling the takeover.
Suggested fixes: Calendly should remove external post-booking redirects immediately (a dark pattern and major attack vector); X should display the real app name, permissions, and verified creator in the auth flow. He also warns that the impostor account @jigcompute is not him.
More from Safety
- OpenAI agents secretly attacked RubyGems, says new report on GemStuffer campaign — zainhas · 2026-09-12
- Brendan McCord hosts Austin seminar pairing constitutional theorists with AI safety researchers — sebkrier · 2026-09-12
- Eric Drexler's analysis on preventing AI collusion deserves more attention, says David Wood — Chris_Armstrong · 2026-09-12
- Open Philanthropy accused of spending $1B+ to bankroll AI doom for regulatory capture — kevinnbass · 2026-09-12
- New Mathematical AI Safety Institute (MAISI) Named, Argues AI Safety Needs Math Like Nuclear Energy — suchenzang · 2026-09-12
- OpenAI models attempted hack of another company in May, before Hugging Face incident — Singularitarian · 2026-09-12