X (formerly Twitter) has mandated that all users relying on hardware security keys or passkeys for two-factor authentication (2FA) must re-enroll their credentials by November 10. This requirement is driven by the platform's transition from the twitter.com domain to x.com, which affects how security keys are cryptographically tied to web domains. Security keys registered under twitter.com will not function for authentication on x.com, necessitating the re-enrollment process to maintain account access.
The company clarified that this change is not related to any security breach or incident, but is a technical necessity due to the domain migration. Only users utilizing physical security keys or passkeys are impacted; other 2FA methods such as authenticator apps or SMS codes remain unaffected. Users who do not re-enroll their security keys by the deadline risk being locked out of their accounts until they update their credentials or switch to another authentication method. X emphasized that this move also aligns with its broader commitment to modern authentication standards and the eventual retirement of the Twitter brand and domain.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
November 10, 2025 was the cutoff date X gave users to re-enroll their passkeys and hardware security keys before risking being locked out of their accounts.
In follow-up reporting, X stated the passkey reset requirement was caused by the shutdown of twitter.com rather than any security problem or breach. This clarified the reason for the re-enrollment request as an infrastructure/domain transition.
X warned users that as it retires the legacy twitter.com domain, they must re-register passkeys and hardware security keys used for two-factor authentication to avoid account access issues. The company set November 10, 2025 as the deadline for re-enrollment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.