October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

X’s Twitter.com-to-X Rebrand Created a Phishing-Enabling URL Bug

A reported X iOS app change made some links containing “twitter.com” look like different domains, while leaving their destinations unchanged. Here’s what happened and how to spot deceptive links.
From TheFinanceBase Team4 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In April 2024, a reported change in X’s iOS app could make a link to a lookalike domain such as netflitwitter.com appear to say netflix.com. The underlying link could still lead to netflitwitter.com. That mismatch created a phishing opportunity by making a deceptive destination look familiar—not a confirmed mass account breach.

What X changed in April 2024

Contemporaneous reports said X’s iOS app automatically substituted the text twitter.com with x.com in links posted on the platform. The rule was reported to affect the string within other domain names, not only X’s own old address. The behavior became public around April 8, examples circulated over the following days, and reports on April 10–11 said X had corrected or narrowed it. Gizmodo’s April 10 report and Ars Technica’s April 11 account describe the change and its risks.

The reports identified the iOS app as the main affected surface. They do not establish that Android, desktop browsers, every X client, or every post behaved the same way. Nor do they document a precise patch version or prove that all patterns disappeared at once.

How a domain could look like another brand

A domain name is not ordinary prose: changing characters inside it can change what a reader thinks a link is, without changing where the link goes. In the reported example, the display could be altered while the stored destination remained different:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Domain in the posted link: netflitwitter.com
  • Text that could appear in the affected client: netflix.com
  • Destination on click: netflitwitter.com

netflitwitter.com is not netflix.com. The apparent resemblance came from X’s reported rendering behavior; it did not mean the lookalike domain belonged to Netflix. Security coverage discussed other examples, including setwitter.com appearing as sex.com, illustrating that the replacement could affect a substring inside a larger domain. KrebsOnSecurity and The Register covered the phishing implications and examples.

Why this was a phishing risk, not proof of a breach

The security problem was a gap between what users saw and what their taps opened. A familiar-looking label can influence a trust decision before a person checks the browser’s address bar. If a deceptive destination then asks for a login, payment, or account verification, the display mismatch can help an attacker make the request seem more credible.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The reported behavior did not itself steal passwords, and the sources cited here do not establish a large-scale successful credential-theft campaign. It is more precise to call it a phishing-enabling flaw or opportunity than to say X was hacked or users’ credentials were stolen. It also was not necessarily an HTTP redirect: the reported issue concerned the displayed text and the underlying link target. A site can separately redirect after a click, which is why checking the final address matters too.

What X reportedly did—and what remains unclear

Reports said X reversed or narrowed the substitution within roughly a day or two of the issue gaining attention. Coverage differed on the completeness and timing of the correction, and the reporting did not provide an authoritative public postmortem explaining the implementation. The available evidence therefore supports a quick reported correction, not a precise statement about a universal fix date or client-by-client rollout.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

X’s current harmful-link guidance says the company uses internal tools, user reports, third-party vendors, and industry partners to identify harmful URLs. That general detection system is separate from the rendering problem described here; a warning or block system is not a substitute for showing users the destination accurately. X’s guidance on fake emails says it will not ask for a password by email, direct message, or reply.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why both twitter.com and x.com still mattered

Rebranding a service does not instantly remove its old domain from links, support pages, emails, and third-party references. During the transition, users could encounter both twitter.com and x.com, and the two could produce different outcomes depending on the URL, browser, device, or login state. Ars Technica later reported on the continuing migration of URLs and the uneven transition in its May 2024 coverage.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The important distinction is between a company migrating its own pages and a platform rewriting text inside user-submitted domains. Redirects, canonical links, and careful server-side migration can preserve a relationship between an old address and its replacement. Broadly editing a character string in arbitrary links can instead make the visible label disagree with the destination. A verified account, a link preview, or an X-owned-looking word somewhere in a domain does not resolve that mismatch.

How to check a link before entering credentials

  1. Do not trust the post’s displayed text alone. A label can differ from the actual hyperlink target.
  2. Open cautiously and inspect the browser address bar. Check the destination after any redirect, not just the first address.
  3. Identify the actual domain. netflix.com is a different domain from netflitwitter.com. A brand name embedded in a longer domain—such as brand-login.com, brandtwitter.com, or brand.com.example.net—does not make that domain the brand’s official site.
  4. Be wary of pressure and odd destinations. Misspellings, unfamiliar country-code domains, shortened links, and urgent login, payment, giveaway, or verification requests deserve extra scrutiny.
  5. Navigate independently for sensitive tasks. Type the service’s known address yourself or use a saved bookmark instead of following an unsolicited login link.
  6. Do not enter an X password on a page reached through a suspicious link. X’s stated policy is not to request passwords by email, direct message, or reply.

HTTPS does not prove that a site belongs to the brand you intended to visit. It encrypts the connection to the domain shown; a deceptive domain can also use HTTPS. A password manager may refuse to autofill on an unfamiliar domain, which can be a useful warning, but it is not proof of safety. Likewise, platform link warnings can help, yet users should not assume every suspicious destination will be blocked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you entered credentials on a suspicious page

  • Go to the service using its known address or app, then change the password there.
  • Revoke active sessions if the service offers that control.
  • Enable multifactor authentication.
  • If you reused the password elsewhere, change it on those accounts as well.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.