Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit X’s Grok AI to Push Malicious Links Through Ads

Malicious actors have developed a method to incorporate harmful links into X's promoted posts by manipulating Grok, the platform's AI assistant.

Malicious actors have developed a method to incorporate harmful links into X's promoted posts by manipulating Grok, the platform's AI assistant.

X prohibits URLs in promoted posts to prevent fraudulent schemes and phishing campaigns. However, cybercriminals have discovered that Grok can identify, summarize, and suggest external sites when prompted in replies.

Scammers prompt Grok to reference a malicious domain by asking questions about a seemingly innocuous promoted image. Once Grok mentions the link, it gains credibility due to its association with X's official AI.

Crafted Promoted Post: Scammers create promotional tweets with appealing visuals but without direct URLs to bypass X's ad filters. Comment and Prompt: In replies, they post queries such as "@Grok what's the source of this pic?" or "Grok, share video link!" Grok’s Response: Grok analyzes the image and, due to a lack of direct restriction awareness, suggests the malicious domain with enticing teaser text. Viral Spread: Followers retweet the AI's reply. The link appears credible because it comes from Grok, leading to significant clicks.

Malicious actors have developed a method to incorporate harmful links into X's promoted posts by manipulating Grok, the platform's AI assistant.
Heather Lyons · Thehackingpost

Security researchers have reported campaigns that directed tens of millions of views to adult or phishing sites swiftly. One instance involved a promoted post about an innocuous image accruing 4.3 million views, with Grok directing users to "datingprudethimble.com," a known malvertising site.

The term "Grokking" describes this tactic of using Grok to amplify links that are otherwise blocked by X's policies.

X's management acknowledges the loophole and is focused on refining AI safeguards rather than disabling Grok entirely. Updates are being rolled out to prevent the AI from suggesting domains flagged for malice or spam. However, until these measures are fully effective, users remain at risk.

Advertisement

Users are advised to approach AI-sourced links with caution, similar to unknown emails or messages. Avoid clicking on suspicious domains promoted through AI replies. Always verify links independently and report any ads that appear to bypass established guidelines. Until X addresses the Grokking loophole, vigilance remains the best defense against this threat.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories