Meta’s failure here is authorization design, not “the bot got fooled.” The claimed exploit path is concrete: use a VPN near the target’s usual hometown, request an Instagram password reset, move into Meta’s AI support assistant, ask it to attach a new email, then receive the one-time code at the attacker-controlled address. The Obama White House and U.S. Space Force Chief Master Sergeant accounts were briefly defaced, and the attackers claimed short handles had resale value above $500,000.
The ugly detail is MFA. The attackers reportedly said the exploit failed against accounts with Instagram MFA enabled, even SMS codes. That pins the issue on Meta’s recovery workflow: an AI layer with authority to change account email state lacked a hard second-factor gate or human review. LLMs in support can cut ticket load, sure. Once the model can mutate identity records, prompt hardening is theater; policy enforcement has to sit outside the chat loop.