X Has a CSAM Problem Hiding in Plain Sight. Why Is It Still This Easy?

Warning Screen

Content warning: This article discusses child sexual abuse material and online exploitation. We deliberately do not reproduce specific search terms, accounts, links, or exact hashtag combinations that could help someone locate illegal material. Do not go looking for it.

There is something deeply wrong with X.

Not because child sexual abuse material, commonly abbreviated as CSAM, exists somewhere on the platform. Tragically, CSAM exists across the internet and has appeared on virtually every major social network at one point or another.

What makes the situation on X disturbing is how visible, persistent and apparently discoverable the material has become.

In June 2026, EL PAĂŤS independently investigated X and reported that apparently innocent hashtags were being flooded with illegal videos involving minors. The newspaper found that basic keyword searches could lead to this material and deliberately refused to publish the hashtags involved because doing so could make the content easier to find.

That investigation was not describing an isolated incident.

The problem has been documented for years.

When Elon Musk acquired Twitter in 2022, he publicly said eliminating child exploitation material would remain a top priority. Yet reporting in 2025 found networks continuing to advertise CSAM through hashtags, automated accounts and X Communities. NBC News found that some of the terminology being exploited even incorporated references to Omegle, the now defunct video chat platform notorious for child safety problems. The investigation concluded that activity which had previously appeared as a trickle had grown substantially, with automated accounts contributing to the volume.

That matters because it undermines one of the easiest explanations for the problem: that criminals are hiding behind extraordinarily elaborate codes which moderators simply cannot decipher.

Some undoubtedly are.

But reports from both NBC and EL PAĂŤS indicate that abuse networks also exploit ordinary or seemingly unrelated hashtags. You do not necessarily need some underground dictionary of coded terminology to stumble into the wrong corner of X.

We have seen the same phenomenon ourselves while using the platform. That observation is anecdotal rather than scientific, but it is precisely what makes the issue so unsettling: you should not need to intentionally search for CSAM before a mainstream social network becomes capable of exposing you to it.

And nobody should test this claim by searching for it.

You should not have to search for it. The platform can bring it to you.

The modern social network is not merely a collection of posts arranged chronologically.

It is a recommendation machine.

Hashtags connect content. Accounts follow other accounts. Engagement influences distribution. Recommendations move users from one post to another. Networks of automated accounts can amplify one another. Once an illegal distribution network manages to establish itself inside that machinery, deleting individual posts becomes a glorified game of whack a mole.

Alliance4Europe documented what it described as coordinated networks hijacking hashtags on X. Its researchers reported individual posts, which X removed, but found that the broader operation continued. Their conclusion was that removing accounts individually was insufficient because replacement accounts simply continued the operation.

This is the fundamental distinction that X needs to answer.

Can X remove a CSAM post once somebody identifies it?

Almost certainly.

Can X prevent networks from repeatedly uploading, advertising, recommending and redirecting users toward CSAM?

The evidence being presented by journalists, researchers and regulators suggests that question remains very much unresolved.

Then there is the moderation problem

It is tempting to simplify this into “X replaced moderators with AI.”

The reality is more complicated, and frankly the real numbers are concerning enough without embellishing them.

X says it uses a mixture of machine learning, automated enforcement and human moderation. Its own transparency reporting shows that automation performs an enormous amount of enforcement. In its July to December 2024 figures, approximately 1.73 million of 1.79 million Child Safety account suspensions were automated, although most reports X sent to NCMEC during that period had gone through human review.

At the same time, X reported 2,294 people working in content moderation in 2023. By its April 2025 DSA transparency report, that figure had fallen to 1,486, a reduction of roughly 35%.

Automation is not inherently the problem. At the scale of a global social network, automated detection is essential. Hash matching can identify previously known CSAM with extraordinary efficiency. Machine learning can flag suspicious new material for review.

But automated systems also have limits. New material does not necessarily match existing hashes. Algorithms produce false positives and false negatives. Context matters. Networks change terminology and accounts. Human investigators are still needed to identify patterns, review ambiguous material and disrupt entire networks rather than individual uploads. EL PAÍS reported that X’s relationship with child safety technology organization Thorn ended in 2025 after Thorn said X had failed to pay outstanding invoices; X subsequently said it was expanding its own CSAM detection technology.

Then X added another problem to the pile: Grok.

In January 2026, Ofcom opened a formal investigation after reports that Grok functionality integrated into X was being used to create sexualized images that could constitute CSAM. The European Commission separately opened a formal Digital Services Act investigation into Grok and expanded its examination of X’s recommender systems, specifically citing risks involving dissemination of illegal content and material potentially amounting to CSAM.

So X is simultaneously trying to use increasingly sophisticated automation to police abuse while operating generative technology that regulators say may itself have introduced new child safety risks.

Humanity has somehow managed to invent a machine capable of creating the problem and another machine tasked with finding the problem. Perhaps we should not be shocked that this arrangement occasionally proves inadequate.

Back in 2024, Facebook had a similar problem, which they fixed.

It wasn’t CSAM related, but their shorts feature was filled with adult content. After many online publications started noticing, META was quick to act and fixed the problem. Why can’t X? For more info on FB issue, see (NSFW):

“This isn’t isolated to X” is true. It is also not a defense.

This point needs intellectual honesty.

X is not the only major platform with a child exploitation problem.

NCMEC received 21.3 million CyberTipline reports in 2025, containing approximately 61.8 million images, videos and other files connected to suspected child exploitation. CSAM remained the largest reporting category.

Meta cannot exactly climb onto the moral high ground here either. Just this week, WIRED reported that researchers discovered more than 50 Meta advertisements containing abusive or sexualized AI generated imagery involving children, some of which had apparently remained in Meta’s advertising systems for months.

So if X says the problem exists elsewhere, X is correct.

But that argument answers the wrong question.

The question is not:

Does CSAM exist anywhere else on Earth?

The question is:

Why can coordinated accounts repeatedly exploit a major public social network to expose, advertise or funnel users toward this material, sometimes through apparently ordinary discovery mechanisms?

If your restaurant has rats in the kitchen, informing the health inspector that another restaurant also has rats is technically useful information. It is not a sanitation policy.

Our own experience has been that we have never encountered comparable material on other mainstream social networks through normal browsing. That is anecdotal and cannot establish which platform has the most CSAM. Reporting statistics cannot cleanly answer that question either, because high reporting numbers can indicate either more abuse or better detection and reporting.

But the persistent public discoverability documented on X deserves scrutiny on its own merits.

So why isn’t anyone reacting?

They are.

Just not with the speed or spectacle people understandably expect when the crime involved is this serious.

As of August 7, 2026, Ofcom’s investigation into X remains officially open. Under the UK Online Safety Act, Ofcom can ultimately impose penalties reaching the greater of £18 million or 10% of qualifying worldwide revenue. In severe cases of continuing noncompliance, it can seek court ordered measures capable of disrupting a platform’s business or even blocking access in the UK.

The European Commission is formally investigating X under the Digital Services Act, including its handling of illegal material and risks introduced by Grok.

Australia has been fighting X over child safety transparency for years. In May 2026, Australia’s Federal Court ordered X Corp. to pay a AUD 650,000 civil penalty after it failed to fully comply with an eSafety transparency notice concerning its measures against child sexual exploitation material.

So institutions are reacting.

The more uncomfortable question is whether regulatory investigations lasting months or years are remotely proportionate to how rapidly these networks operate.

An automated account can be replaced in minutes.

A regulatory case can take years.

There is the mismatch.

Why aren’t police chasing the uploaders?

They are doing that too.

Under U.S. law, online providers have reporting obligations when they obtain actual knowledge of apparent child exploitation offenses. Those reports feed into NCMEC’s CyberTipline and then into law enforcement systems.

NCMEC says more than 53,000 reports involving urgent situations or children potentially in imminent danger were escalated to law enforcement in 2025 alone.

And prosecutions do result.

For example, South Carolina authorities announced in March that CyberTipline reports led investigators to several suspects accused of CSAM offenses. One of them, Terry Wayne Harwood, was arrested on multiple felony charges. In July, xAI itself filed a civil lawsuit against Harwood alleging misuse of Grok in connection with illegal material. The criminal allegations remain subject to the normal presumption of innocence.

But identifying uploades is not always simple. Offenders operate internationally. They use disposable accounts, automated networks and third party platforms. NCMEC reports are routinely routed across borders, meaning multiple companies and law enforcement jurisdictions can become involved before authorities even establish who is sitting behind an account.

Why aren’t authorities “busting down X’s doors?”

Because a platform containing criminal material and a company itself committing a prosecutable criminal offense are not automatically the same thing.

Investigators need evidence. Regulators have statutory procedures. Courts require legal thresholds. Corporate liability, individual criminal liability, platform reporting obligations and failures in content moderation are different legal questions.

That due process is necessary.

But due process should not become an excuse for regulatory paralysis.

If credible investigations repeatedly demonstrate that the same distribution techniques continue working for months, then authorities should be asking a harder question than whether individual posts were eventually removed.

They should ask whether X’s systems themselves are adequately designed to prevent predictable, repeated exploitation.

That is precisely the type of systemic question now sitting before Ofcom and the European Commission.

When does this stop?

Probably not when another thousand accounts are banned.

It stops when maintaining a CSAM distribution network on a mainstream platform becomes structurally difficult: known material is blocked automatically, suspicious new material reaches trained human reviewers rapidly, interconnected abuse networks are removed as networks rather than as individual accounts, recommender systems stop amplifying them, payment and external distribution infrastructure is disrupted, platform operators preserve evidence and cooperate rapidly with police, and regulators impose consequences large enough that inadequate child safety systems become more expensive than fixing them.

X publicly describes child sexual exploitation as something for which it has “zero tolerance.” Its policy says offending accounts can be permanently suspended and reported to NCMEC.

The standard therefore should not be mysterious.

Zero tolerance should produce something reasonably close to zero discoverability.

Four years after Elon Musk called eliminating this material a top priority, credible journalists are still finding it hidden in plain sight. Regulators are investigating. Governments are issuing penalties. Researchers continue documenting networks that regenerate after individual accounts disappear. ([EL PAĂŤS English][1])

  • At some point, “we removed the accounts” stops being an answer.

  • The questions now are much simpler.

  • Why did the system allow them to flourish in the first place?

  • Why can they come back?

  • Why can ordinary users encounter their material?

And how many more investigations will it take before a platform with X’s technological and financial resources is expected not merely to react to child exploitation, but to make its infrastructure genuinely hostile to it?

Children should not have to wait for that answer.

1 Like