Dev exposes sophisticated phishing attempt spoofing an official x.ai address
threepointone · x · 2026-10-10
Developer threepointone flagged a new sophisticated phishing attempt in which the message appeared to come from an official x.ai email address, leaving him puzzled about how the sender address was spoofed. Another developer forwarded it with analysis suggesting the attack came via inbound channels.
A useful warning for AI practitioners: apparent official domains in email can still be spoofed or abused, so sender verification matters.
More from Safety
- Beijing pilot issues ID cards for AI digital humans, complete with crypto wallets — Promptmethus · 2026-10-10
- New phishing wave on X: fake invitation links lead to spoofed x.com login page — dejavucoder · 2026-10-10
- Semafor names Altman, Huang, Nadella, Su as co-chairs of tech-policy initiative — ylecun · 2026-10-10
- Baseten launches Project Beacon with Goodfire for inline open-model safety — baseten · 2026-10-10
- Skill Constellations: first dated copy network of 2.1M agent-skill adoptions on GitHub — UBC-O · 2026-10-10
- OpenAI Dot reportedly takes desktop screenshots without notification despite user rules — alexcovo_eth · 2026-10-10