@BenjaminDEKR: First I've heard of this: "Add a secret string to the end of your X email prefix using a '+' (such as john.smith+privat…

X AI KOLs Following News

Summary

A user warns about a phishing attempt disguised as a security tip for X/Twitter, advising users to add a secret string to their email prefix; another user clarifies it's phishing and recommends using passkeys instead.

First I've heard of this: "Add a secret string to the end of your X email prefix using a '+' (such as john.smith+private@gmail)" Any more info on how this works?
Original Article
View Cached Full Text

Cached at: 07/05/26, 10:30 AM

First I’ve heard of this:

“Add a secret string to the end of your X email prefix using a ‘+’ (such as john.smith+private@gmail)”

Any more info on how this works?

Nikita Bier (@nikitabier): This is phishing. Do not trust any email that directs you to a website that is not https://t.co/gb12KS6JUU.

To ensure the highest level of security on your account, go to Settings:

• Use passkeys • Add a secret string to the end of your X email prefix using a “+” (such as

Similar Articles

XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None

Lobsters Hottest

The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.