Dev exposes sophisticated phishing attempt spoofing an official x.ai address

threepointone · x · 2026-10-10

Developer threepointone flagged a new sophisticated phishing attempt in which the message appeared to come from an official x.ai email address, leaving him puzzled about how the sender address was spoofed. Another developer forwarded it with analysis suggesting the attack came via inbound channels.

A useful warning for AI practitioners: apparent official domains in email can still be spoofed or abused, so sender verification matters.

Related event: Developers report sophisticated phishing emails spoofing x.ai's official domain(5 posts)→

Original post →

More from Safety

Safety channel →