vulns.co
/
GKData.io MCP

IDAuthentication and identity · 1 min read

Instagram mobile account recovery had inconsistent verification limits

The cited researcher documents a USD 30,000 award for this finding.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

Account recovery relied on verification limits that did not provide a consistent account-level security boundary under concurrent activity. Centralized, atomic attempt accounting is the defensive concern.

Demonstrated impact

The researcher demonstrated unauthorized password reset and reports remediation before publication.

Lessons for review

  • Bind recovery attempts and verification state to the intended account.
  • Use atomic security counters and test concurrent state transitions locally.

Award and evidence

USD 30,000Bug Bounty · Researcher Reported

Individual finding, distinct from the researcher’s other Instagram recovery report; exact award/payment dates are unknown.

Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.

  • The current 2024 article header is not the original disclosure date
  • Exact report, fix, and award dates are unavailable
  • Distinct from the August 2019 device-binding report
  • Current article update: 2024-10-19; original publication is stored separately.

Recorded timeline

Published
2019-07-14explicit · Original publication date preserved by the author’s archive; current article header is a later update.

Sources and provenance

  1. Instagram mobile account recovery had inconsistent verification limits Laxman Muthiyah · reviewed 2026-10-02
  2. Original publication archive Laxman Muthiyah · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software