A bug Twitter downplayed in 2012 resurfaces as researchers hijack celebrity accounts to send tweets by using a UK mobile phone number tied to an account
Context & Ripple Effects
Researchers have revived a flaw Twitter downplayed in 2012 to send tweets from celebrity accounts by binding a UK mobile phone number to those accounts — a reminder that the company's phone-number recovery path has been a recurring weak point rather than a one-off slip. The same surface area shows up again in later coverage: a researcher who says he matched 17M phone numbers to Twitter accounts through the Android app before being blocked, and a confirmed 2022 bug used to link phone numbers and emails to user profiles, with a threat actor offering 5.4M scraped records for sale.
What makes this episode matter is the pattern, not the single exploit: each disclosure forces Twitter to patch one vector while the underlying design — treating a phone number as both an identity anchor and a recovery credential — keeps producing new attack paths.
First-order effects
- Celebrity and high-profile users face immediate account-takeover risk through the phone-number binding path, since any number they control can be re-associated with their profile by an attacker.
- Twitter must emergency-patch the number-binding flow again, six years after first downplaying the flaw, and explain why the 2012 report did not result in a durable fix.
Second-order effects
- Security researchers gain leverage in disclosure disputes: demonstrating live hijacks of famous accounts makes it harder for Twitter to characterize such bugs as low-severity theoretical issues.
- Advertisers and brand-safety teams watching the platform's security posture get fresh evidence that account integrity on Twitter depends on infrastructure fixes, not just content moderation.
Third-order effects
- If phone numbers keep serving as identity anchors across platforms, regulators and auditors are likely to treat identifier-binding flaws as systemic account-security failures rather than isolated bugs — pushing platforms toward decoupling recovery credentials from public-facing handles.
- The 2012-downplay-then-2018-exploit arc becomes a case study in why bug reports dismissed as edge cases tend to resurface at higher severity, shaping how researchers escalate disclosures against large social platforms.
The trend: Phone-number-based identity and recovery systems are becoming the most repeatedly exploited attack surface on major social platforms, with each patched variant exposing the next.