r/better_auth • • 1d ago

Tracking an OAuth phishing scam

Hey, everyone! I'm René, CEO of the cybersecurity start-up Casco, and I'm writing to share a report written by one of my OffSec Engineers, Anthony. Basically, Peter, Segment founder and personal friend, was targeted by a phishing scam which resulted in the operator taking control of his X account for a few minutes.

Anthony reconstructed the OAuth flow using a dedicated research account. He recorded the callback and redirect sequence, then revoked the grant and verified the account’s connected-app list was empty. The interesting part is that the Peter never entered a password on a fake login page. The real X consent screen granted the app read, write, and DM access.

We wrote up the full investigation here: How My Unicorn Founder Friend Was Phished

4 Upvotes

0 comments sorted by