Search the site
Press ESC to close
LIVE
Loading...
Updating...

Nano Labs Founder Recovers X Account Following AI-Linked Phishing Attack

Fact-checked
2 min read
355 words
Share

Jack Kong, the founder of the specialized integrated circuit design firm Nano Labs, has officially regained control of his account on the social media platform X. The recovery follows a sophisticated security breach where attackers managed to hijack the high-profile profile to disseminate fraudulent project information. The incident highlights emerging vulnerabilities in digital security, particularly regarding the intersection of artificial intelligence (AI) and social engineering.

Mechanism of the Phishing Exploit

The breach originated when Kong received a deceptive email sent to his publicly listed contact address. According to statements from the founder, the attack was successful due to a technical oversight involving an AI assistant. The automated tool incorrectly flagged a malicious link within the email as an official X verification page.

  • The attacker targeted a frequently used public email address associated with the founder.
  • An AI tool provided a false sense of security by misidentifying the phishing site.
  • The victim entered a two-factor authentication (2FA) code into the fraudulent interface.
  • This allowed the malicious actors to bypass security protocols and take full control of the account.

Impact and Immediate Security Response

During the period of unauthorized access, the compromised account was utilized to spread false project information and potentially malicious links to Kong’s followers. This tactic is common in the cryptocurrency sector, where hijacked accounts of industry leaders are often used to promote fake airdrops or fraudulent token launches.

"The AI assistant mistakenly identified a fake link in the email as the official X verification page", Kong explained, noting that the error led to the unintended disclosure of his verification credentials.

Industry experts note that this incident serves as a warning about the limitations of relying solely on AI filters for cybersecurity validation.

The recovery of the account on September 28, 2026, marks the end of the immediate threat to Kong’s digital identity. However, the event underscores the necessity for multi-layered security approaches within the blockchain and semiconductor industries. As attackers refine their methods to bypass standard 2FA by exploiting human and AI trust, stakeholders are encouraged to verify all communication through multiple official channels before providing sensitive credentials.

Frequently Asked Questions

Quick answers to the most common questions about this topic.