Digital Deception: X’s Hidden Feature That Ripped the Mask Off State-Sponsored Sockpuppets

X platform About your account privacy settings showing location exposure options

Digital Deception: X's Hidden Feature Quietly Unmasks Anonymous Users

How a buried transparency tool became an identity-exposure engine — and what you still don't know about what X collects

Reading time: 8 min

Last November, X rolled out a feature it called "About this account" — a small link tucked beneath your join date, promising transparency. The pitch was simple: help users spot bots and fake profiles by showing where an account is based, how many times it changed its username, and which app store it came from. What X didn't advertise was the other side of the coin. For journalists, activists, and anyone who built a pseudonymous presence on the platform, that same transparency panel became a geolocation tool. Your country — or at least your continent — was now public metadata, and a planned VPN warning system threatened to flag anyone trying to mask their location. The feature wasn't just revealing; for some users, it was exposing.

What "About This Account" Actually Reveals

Click the "Joined" date on any X profile and a panel slides open. It lists four data points: your account's original creation date, your current country or region, the number of username changes you've made (and when the last one occurred), and the platform you used to download X — the U.S. App Store, Google Play, or a web browser. On paper, this reads like a fraud-prevention toolkit. In practice, it functions as a de-anonymization layer that most users never opted into.

The country field is the sharpest blade. X allows you to switch between displaying your specific country or a broader region, but the default is country-level precision. For a dissident in a nation where free expression carries penalties, that default is not a convenience — it's a liability. TechCrunch reported in November 2025 that even U.S.-based users could toggle this setting, but the option was buried three menus deep under Privacy and Safety, labeled "About your account." Most users never find it.

The X app interface showing how location metadata is surfaced to anyone viewing a profile

Then there's the username history. Every handle change you've ever made is now a breadcrumb trail. Someone who switched from a personal name to a pseudonym, or from a regional identity to something neutral, can be traced backward through those changes. The timestamp on the most recent change is precise — down to the day — which means someone correlating it with a public event can narrow your identity window dramatically.

The VPN Warning Nobody Asked For

Reverse engineers digging through X's app code in late 2025 found something more alarming: a planned warning label for accounts using VPNs or proxies. The message, still in development as of this writing, would read: "Your country or region may not be accurate." On its face, this sounds like a helpful disclaimer. In context, it's a scarlet letter.

Consider what this means. A journalist in a conflict zone uses a VPN to protect their physical safety. X's proposed system would flag that protection as suspicious — not to the user, but to everyone viewing their profile. The warning doesn't say "this user values privacy." It says "this user's location data is unreliable," which, in the inverted logic of platform transparency, reads as "this user is hiding something." The chilling effect is immediate: either abandon your VPN and risk real-world exposure, or accept a permanent badge of distrust on your public profile.

X head of product Nikita Bier responded to a user requesting location transparency with "Give me 72 hours" — and the feature appeared days later. The speed of that delivery suggests these tools were already built, waiting in the codebase for a nudge. The VPN warning, discovered by reverse engineer Aaron in November 2025, appears to be following the same trajectory.

The Data X Collects Beyond the Profile

While "About this account" grabs headlines, it's merely the visible tip of a much larger data iceberg. Since Elon Musk's acquisition in October 2022, X's privacy policy has expanded its collection scope in directions that make the profile transparency panel look quaint by comparison.

$150MFTC fine for misusing 2FA data
80%Staff reduction post-acquisition
2042Year FTC monitoring expires
$44BMusk acquisition price

In September 2023, X updated its privacy policy to explicitly permit collection of biometric data — facial recognition, fingerprints, and behavioral markers — for "safety, security, and identification purposes." The company stated this would be "based on your consent," but the mechanism for withholding that consent remains opaque. The same update expanded employment history collection, pulling job titles, skills, and search behavior into X's advertising and recruitment targeting systems.

By October 2024, X added another clause: all posts, regardless of privacy settings, could be used to train generative AI models. There is no opt-out. Your pseudonymous poetry, your locked-account venting, your deleted drafts — if they touched X's servers, they're training data now. This isn't hypothetical: Musk's xAI acquired X in March 2025 for $33 billion in an all-stock deal, folding the platform's data directly into the same AI pipeline that powers Grok.

"

No one was responsible for about 37 percent of X Corp.'s privacy program controls.

— Federal Trade Commission filing, 2023

The FTC has been watching this closely. In a 2022 settlement, Twitter (as it was then called) agreed to pay $150 million and submit to 20 years of independent privacy audits after admitting it had used phone numbers and email addresses collected for two-factor authentication to target ads. Musk tried to terminate that oversight order in 2023, arguing bias; he failed. In May 2026, he tried again, claiming X's merger into xAI and then SpaceX made the original entity disappear. The FTC's public comment period on that petition runs through July 2, 2026 — and early submissions overwhelmingly oppose lifting the order. One commenter put it bluntly: "Without the standards set by the FTC, Twitter could roll back their privacy measures for the sake of cost cutting without any consequence."

How Platform Transparency Became User Exposure

There's a genuine tension here that X's communications never address. Transparency about accounts is not the same as transparency about the platform. Instagram has offered "About this account" since 2018 without triggering the same backlash because Meta designed it as a user-facing fraud tool, not a public metadata broadcast. X's version flips the architecture: the data is exposed to viewers, not just to the account holder reviewing their own footprint.

The difference matters. When you can see your own login history and device list, that's security. When a stranger can see your country, your username history, and your app store origin, that's surveillance dressed in accountability clothing. X's framing — "reduce inauthentic engagement" — assumes all users are potential threats to be verified, rather than individuals with legitimate reasons to obscure their location.

FeatureStated PurposeActual Risk
Country/region displaySpot fake location claimsExposes dissidents, journalists, abuse survivors
Username change historyTrack account rebrandingDe-anonymizes users who switched to pseudonyms
App store originIdentify bot creation patternsReveals device ecosystem and economic tier
VPN warning (planned)Flag inaccurate location dataPenalizes legitimate privacy protection
Biometric collectionPrevent impersonationCreates irreversible identity database
AI training opt-outNot applicable — mandatoryPermanent repurposing of all user content

The irony is thick enough to cut. X markets itself as the "digital town square" where free speech reigns, yet its infrastructure increasingly resembles a panopticon where every participant is tagged, tracked, and potentially unmasked. The platform that reinstated banned accounts in the name of open discourse simultaneously built tools that make anonymous discourse structurally impossible.

What You Can Still Do

The controls that exist are scattered and partially effective. Under Settings → Privacy and Safety → About your account, you can switch from country to region display — but this only affects the "About this account" panel, not the underlying data X holds. You can review your username history, though you cannot delete it. You can disable location services in your device settings, though X may still infer location from your IP address and app store.

For the VPN warning specifically, there is no toggle yet because the feature hasn't launched. When it does, the only guaranteed protection will be using X exclusively through a privacy-focused browser with script blocking and fingerprint randomization — a level of technical sophistication far beyond what casual users possess. The platform's design assumes you either accept full visibility or accept being flagged as deceptive. There is no neutral ground.

The Broader Pattern: Privacy as a Feature, Not a Default

X is not unique in this trajectory, but it is the most aggressive case study. Since Musk's takeover, the platform has dissolved its Trust and Safety Council, cut approximately 80% of its staff, and shifted from professional moderation to crowd-sourced Community Notes. The privacy infrastructure has followed the same pattern: fewer humans overseeing more automated data collection, with user-facing controls becoming afterthoughts rather than design principles.

Consider the timeline. In January 2023, X cut off third-party clients and began charging for API access, killing tools that let users interact with the platform without surrendering to its native tracking. In June 2024, likes were made private — but only for viewers, not for X itself, which still uses that engagement data for algorithmic ranking. In October 2024, the block function was neutered: blocked accounts can still see your public posts, they just can't reply. The message is consistent: your content is public by architectural decree, and your controls are cosmetic.

Academic research published in 2025 confirms the information quality decline. A study in the Harvard Kennedy School Misinformation Review found "consistent evidence of declining average information quality" post-acquisition, driven by algorithmic amplification of engagement over credibility and the departure of high-credibility users. Another study in Science provided causal evidence that exposure to anti-democratic content on X measurably increases political polarization — a finding that directly contradicted earlier Meta-funded research on Facebook and Instagram. The platform isn't just less private; it's structurally more polarizing, which makes the identity-exposure features even more dangerous for vulnerable users.

"

X's algorithm may have moved away from promoting moderate content to reinforcing users' existing preferences more explicitly, especially in out-of-network recommendations.

— ACM Conference on Fairness, Accountability, and Transparency, March 2025

The European Commission isn't ignoring this. In January 2025, it requested X's internal algorithm documentation following accusations of manipulation benefitting far-right viewpoints. The EU's Digital Services Act gives regulators teeth that the U.S. FTC, for all its monitoring, has struggled to deploy quickly. Whether that oversight can outpace X's product velocity is an open question — one that will likely define the platform's regulatory future through 2026 and beyond.

Why This Matters Now

We're at an inflection point where the assumptions of the early social web — that pseudonymity was a valid and protected choice — are being systematically dismantled. X's "About this account" feature is not an isolated tool; it's a prototype for how platforms will balance "authenticity" against anonymity in the AI era. The logic is seductive: bots are a real problem, impersonation is a real problem, misinformation is a real problem. The solution X proposes — total metadata visibility — solves those problems by creating a new one: the elimination of protected identity for anyone who needs it.

Activists in authoritarian states don't need a VPN warning label. Journalists investigating organized crime don't need their country of origin displayed. Abuse survivors rebuilding their lives online don't need their username history searchable. These aren't edge cases; they're precisely the users who made Twitter valuable in its earlier incarnation as a platform for voices that couldn't speak elsewhere. That X is willing to sacrifice them for a marginally cleaner bot detection rate says something about whose convenience the platform now prioritizes.

The deeper question is whether users will accept this trade-off. X's monthly active usage has remained stable at around 29% self-declared engagement as of mid-2025, despite projections that 30 million users would leave by end of 2024. The platform's ad revenue, after collapsing 41% in 2024, is projected to recover 16.5% in 2025 — still less than half its 2021 peak. Users aren't fleeing en masse, but the composition of who stays matters. If pseudonymous voices exit and verified real-name accounts dominate, X becomes a different kind of public square — one where the safest thing to say is also the most boring.

Frequently Asked Questions

Can I completely hide my location on X?

You can switch from country-level to region-level display in Settings → Privacy and Safety → About your account, but you cannot fully hide the location field. X determines this from your IP address, app store region, and device settings. Using a VPN may trigger a planned warning label that flags your profile to other users.

Does X delete my old usernames from its records?

No. The "About this account" panel displays your full username change history with timestamps, and this data is not user-deletable. Even if you change your handle to escape harassment or establish a pseudonym, the trail remains visible to anyone who checks your profile metadata.

Is X's biometric data collection mandatory?

X's privacy policy states biometric collection is "based on your consent," but the opt-out mechanism is not clearly documented. The platform has indicated it will use government ID plus selfie matching for verification, with biometric data extracted from both sources. As of July 2026, this appears limited to premium verification applicants rather than all users.

Can I stop X from using my posts to train AI?

No. X's terms of service, updated in October 2024, state that all posts may be used to train generative AI models with no opt-out available. This applies regardless of whether your account is public or protected, and includes historical content posted before the policy change.

What happens if the FTC loses its oversight of X?

If Musk succeeds in terminating the FTC's 20-year consent order, X would no longer be subject to mandatory independent privacy audits. The company argues it has built a "world-class privacy program," but the FTC notes that layoffs eliminated key compliance staff. Public comments overwhelmingly oppose ending the order, with a decision expected after July 2, 2026.

We welcome your analysis! Share your insights on the future trends discussed, or offer your expert perspective on this topic below.

Post a Comment (0)
Previous Post Next Post