The trick exploits a specific interaction between transparent PNG alpha channels and X's mobile image viewer:
This is not a security vulnerability or a hack in the traditional steganography sense — it is a deliberate exploitation of X's two-stage image rendering pipeline (thumbnail vs. full-resolution viewer). The platform does not apply the same compression or alpha-channel handling in the full-screen view as it does in the timeline, which creates the reveal effect.
No direct evidence has yet surfaced specifically linking kakushie images to active CSAM distribution. However, the safety concern is widely recognized as a credible and serious risk for several reasons:
Key caveat: While there is clear documented evidence of X's systemic CSAM problem and growing regulatory pressure, no specific report or investigation has yet confirmed kakushie images being actively used for CSAM. The concern remains a credible, widely discussed risk rather than a confirmed exploitation vector — but given that the entire technique is designed to hide images from public view, the potential for abuse is obvious and has been flagged by safety researchers.
X is currently under scrutiny from multiple fronts, and the kakushie trend adds a new dimension to these existing concerns. It provides a technically trivial, widely accessible method for any user to post content that is invisible to automated moderation in the timeline and only visible after deliberate user interaction.
| Regulator/Body | Action | Date |
|---|---|---|
| Ofcom (UK) | Formal investigation into X under the Online Safety Act 2023; critical incident protocol order | Jan–Jun 2026 |
| European Commission | Investigating alleged CSAM distribution network on X | Aug 2025 |
| Australian eSafety Commissioner | Warned CSAM is "particularly systemic" on X | Mar 2026 |
| Thorn (NGO) | Terminated partnership with X over CSAM inaction | Jun 2025 |
Until X adjusts its rendering pipeline to apply consistent content moderation scanning at both the thumbnail and full-resolution stages, the platform remains exposed to this exploitation vector.