What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In April 2024, a reported change in X’s iOS app could make a link to a lookalike domain such as netflitwitter.com appear to say netflix.com. The underlying link could still lead to netflitwitter.com. That mismatch created a phishing opportunity by making a deceptive destination look familiar—not a confirmed mass account breach.
What X changed in April 2024
Contemporaneous reports said X’s iOS app automatically substituted the text twitter.com with x.com in links posted on the platform. The rule was reported to affect the string within other domain names, not only X’s own old address. The behavior became public around April 8, examples circulated over the following days, and reports on April 10–11 said X had corrected or narrowed it. Gizmodo’s April 10 report and Ars Technica’s April 11 account describe the change and its risks.
The reports identified the iOS app as the main affected surface. They do not establish that Android, desktop browsers, every X client, or every post behaved the same way. Nor do they document a precise patch version or prove that all patterns disappeared at once.
How a domain could look like another brand
A domain name is not ordinary prose: changing characters inside it can change what a reader thinks a link is, without changing where the link goes. In the reported example, the display could be altered while the stored destination remained different:
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Domain in the posted link:
netflitwitter.com - Text that could appear in the affected client:
netflix.com - Destination on click:
netflitwitter.com
netflitwitter.com is not netflix.com. The apparent resemblance came from X’s reported rendering behavior; it did not mean the lookalike domain belonged to Netflix. Security coverage discussed other examples, including setwitter.com appearing as sex.com, illustrating that the replacement could affect a substring inside a larger domain. KrebsOnSecurity and The Register covered the phishing implications and examples.
Why this was a phishing risk, not proof of a breach
The security problem was a gap between what users saw and what their taps opened. A familiar-looking label can influence a trust decision before a person checks the browser’s address bar. If a deceptive destination then asks for a login, payment, or account verification, the display mismatch can help an attacker make the request seem more credible.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The reported behavior did not itself steal passwords, and the sources cited here do not establish a large-scale successful credential-theft campaign. It is more precise to call it a phishing-enabling flaw or opportunity than to say X was hacked or users’ credentials were stolen. It also was not necessarily an HTTP redirect: the reported issue concerned the displayed text and the underlying link target. A site can separately redirect after a click, which is why checking the final address matters too.
What X reportedly did—and what remains unclear
Reports said X reversed or narrowed the substitution within roughly a day or two of the issue gaining attention. Coverage differed on the completeness and timing of the correction, and the reporting did not provide an authoritative public postmortem explaining the implementation. The available evidence therefore supports a quick reported correction, not a precise statement about a universal fix date or client-by-client rollout.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
X’s current harmful-link guidance says the company uses internal tools, user reports, third-party vendors, and industry partners to identify harmful URLs. That general detection system is separate from the rendering problem described here; a warning or block system is not a substitute for showing users the destination accurately. X’s guidance on fake emails says it will not ask for a password by email, direct message, or reply.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why both twitter.com and x.com still mattered
Rebranding a service does not instantly remove its old domain from links, support pages, emails, and third-party references. During the transition, users could encounter both twitter.com and x.com, and the two could produce different outcomes depending on the URL, browser, device, or login state. Ars Technica later reported on the continuing migration of URLs and the uneven transition in its May 2024 coverage.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The important distinction is between a company migrating its own pages and a platform rewriting text inside user-submitted domains. Redirects, canonical links, and careful server-side migration can preserve a relationship between an old address and its replacement. Broadly editing a character string in arbitrary links can instead make the visible label disagree with the destination. A verified account, a link preview, or an X-owned-looking word somewhere in a domain does not resolve that mismatch.
How to check a link before entering credentials
- Do not trust the post’s displayed text alone. A label can differ from the actual hyperlink target.
- Open cautiously and inspect the browser address bar. Check the destination after any redirect, not just the first address.
- Identify the actual domain.
netflix.comis a different domain fromnetflitwitter.com. A brand name embedded in a longer domain—such asbrand-login.com,brandtwitter.com, orbrand.com.example.net—does not make that domain the brand’s official site. - Be wary of pressure and odd destinations. Misspellings, unfamiliar country-code domains, shortened links, and urgent login, payment, giveaway, or verification requests deserve extra scrutiny.
- Navigate independently for sensitive tasks. Type the service’s known address yourself or use a saved bookmark instead of following an unsolicited login link.
- Do not enter an X password on a page reached through a suspicious link. X’s stated policy is not to request passwords by email, direct message, or reply.
HTTPS does not prove that a site belongs to the brand you intended to visit. It encrypts the connection to the domain shown; a deceptive domain can also use HTTPS. A password manager may refuse to autofill on an unfamiliar domain, which can be a useful warning, but it is not proof of safety. Likewise, platform link warnings can help, yet users should not assume every suspicious destination will be blocked.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
If you entered credentials on a suspicious page
- Go to the service using its known address or app, then change the password there.
- Revoke active sessions if the service offers that control.
- Enable multifactor authentication.
- If you reused the password elsewhere, change it on those accounts as well.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




