Meta 的 AI 支持聊天机器人在帮助黑客窃取并转售知名 Instagram 账号方面表现得异常“得力”——黑客只需让该机器人更改账号关联的电子邮箱地址,同时使用 VPN 隐藏其真实位置即可。
据 404 Media 报道,展示这种“惊人地简单”的利用方式的视频已在黑客和安全研究人员的 Telegram 群组中流传。该漏洞允许黑客在 Meta 于 5 月 29 日实施紧急补丁之前,接管并转售在灰市价值数十万美元的珍贵 Instagram 账号。巴拉克·奥巴马白宫账号以及美国太空军首席军士长账号在被临时入侵期间,也曾发布亲伊朗的图片和消息。
据 404 Media 报道,攻击者只需使用 VPN 将其位置大致匹配到目标 Instagram 账号所在地区,启动密码重置流程,然后要求 Meta 的 AI 支持聊天机器人更改与该账号关联的电子邮箱地址。这是一种非常直接的提示词注入攻击。
Neowin 报道称,该漏洞“已在野外活跃数月,最早可追溯到今年二月,黑客已入侵数千个账号”。但随着近期一些高知名度账号被入侵,该漏洞似乎才在最近几天引起更多公众关注。知名研究员(如 Jane Manchun Wong)近日也报告称其账号被黑。
5 月 31 日,化名开源情报研究员 ZachXBT 在 X 平台上发文称:“Meta 的 AI 支持功能很垃圾,拥有大量访问权限,允许你在无需双重验证的情况下重置任何用户的密码,并且不验证你的身份。”与此同时,研究员 Dark Web Informer 也在 X 平台上描述了同样的漏洞,并指出该漏洞近期已被修复。
根据 CyberSec Guru 的说法,ZachXBT 和 Dark Web Informer 也证实了黑客如何针对并转售特别有价值的 Instagram 账号,包括短用户名 @hey 和 @jowo,其“灰色市场估值合计估计超过 100 万美元”。该安全博客报道称,这类账号即使黑客只持有几天也可能很有价值,原因在于“影响力、转售或品牌冒充”。
广泛的安全漏洞
CyberSec Guru 还描述称,该漏洞代表了计算机安全中经典的“混淆代理”问题,即一个拥有高权限的程序被诱骗,代表权限较低的第三方滥用这些权限。但在本例中,“代理”是一个大语言模型,它拥有“一个你可以用语言引导的概率响应模型”,而不是一个“确定性程序”,后者拥有“需要用代码绕过的硬编码条件判断”。
值得记住的是,即使 Meta AI 支持聊天机器人被利用,用户也有简单的安全解决方案可用。根据 KrebsOnSecurity 的说法,黑客报告称,他们的漏洞攻击对任何启用了多因素认证(MFA)的账号都无效,包括“Instagram 提供的最不健壮的 MFA 形式”,即通过短信发送的一次性验证码。
但该漏洞仍然凸显了科技公司和其他组织急于部署拥有高权限(允许它们修改、创建或删除关键数据)的 AI 智能体所带来的更广泛风险。Meta 于 2026 年 3 月推出了其 Meta AI 支持助手,并承诺它可以“随时为几乎任何支持问题提供可靠的 24/7 全天候支持”。
根据 CyberSec Guru 的说法,要更安全地实现这一点所需的“最低限度”架构应包括“任何账号修改前的带外验证……根据账号风险信号对 AI 发起的重置流程进行速率限制,针对异常 AI 驱动账号修改的操作日志与异常检测,以及一个硬性的确定性门控”。
Meta’s AI support chatbot proved unusually helpful to hackers looking to steal and resell notable Instagram accounts—the hackers simply asking the bot to change the accounts’ associated email addresses while using VPN to mask their true locations.
Videos featuring the “shockingly easy” exploit have been circulating among Telegram groups for hackers and security researchers, according to 404 Media. The exploit allowed hackers to take over and flip valuable Instagram accounts worth hundreds of thousands of dollars on the gray market before Meta implemented an emergency patch on May 29. The Barack Obama White House account and the Chief Master Sergeant of Space Force’s account also posted pro-Iranian images and messages while they were temporarily compromised.
Attackers simply had to use a VPN to approximately match their location to the target Instagram account’s region, begin a password reset process, and then ask Meta’s AI support chatbot to change the email address associated with the account, according to 404 Media. It’s a very straightforward prompt injection attack.
Neowin reported having the exploit as being “active in the wild for months, going as far back as February of this year, with hackers compromising thousands of accounts.” But the exploit seems to have gained more public notice in recent days with the compromise of high-profile accounts. Prominent researchers, such as Jane Manchun Wong, have also recently reported that their accounts were hacked.
On May 31, the pseudonymous open source intelligence researcher ZachXBT posted on X about how “the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.” At the same time, the researcher Dark Web Informer described the same exploit on X while noting it had been recently patched.
Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.
The wide security hole
The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”
It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.
But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”
The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”