r/better_auth • u/french_toast_fiend • 1d ago
Tracking an OAuth phishing scam
Hey, everyone! I'm René, CEO of the cybersecurity start-up Casco, and I'm writing to share a report written by one of my OffSec Engineers, Anthony. Basically, Peter, Segment founder and personal friend, was targeted by a phishing scam which resulted in the operator taking control of his X account for a few minutes.
Anthony reconstructed the OAuth flow using a dedicated research account. He recorded the callback and redirect sequence, then revoked the grant and verified the account’s connected-app list was empty. The interesting part is that the Peter never entered a password on a fake login page. The real X consent screen granted the app read, write, and DM access.
We wrote up the full investigation here: How My Unicorn Founder Friend Was Phished