How I Hacked TikTok's Comment System

Credibility score: 54/100 β€” Mixed Credibility. Several questionable claims detected. Watch with healthy skepticism.

BSmeter analyzed "How I Hacked TikTok's Comment System" and rated it 54/100 for credibility (a BS score of 46/100 β€” mixed credibility), on 2026-07-08. Its weakest claim β€” "Claiming a genuine security vulnerability confirmed by TikTok's team" β€” scored 45/100 and was flagged as confidence mismatch. 7 claims were checked against the video transcript. Scores are produced by BSmeter's AI analysis of the transcript, not independent human verification.

Of 7 claims analyzed: 0 scored under 40, 5 between 40 and 69, and 2 at 70 or above.

Claims analyzed

Setting the scene for a TikTok exploit discovery β€” No Frame (75/100)

At 0:00

Just setting up the story, no claims yet. Straightforward intro to the 'exploit' they found.

Why this score: The speaker is introducing the topic of a TikTok exploit they discovered, describing the initial observation that piqued their interest. This is purely narrative setup, not a claim that requires verification or has a specific rhetorical frame to expose.

Original quote: β€œThis [music] is how I found a TikTok modern day exploit. Recently, someone showed me a TikTok comment under a video that had a badge underneath it saying voted check story in bio.”

Describing a TikTok badge appearing without a poll β€” No Frame (75/100)

At 0:10

Explaining the weird behavior of the badge β€” it's just an observation, not a claim yet. The setup for the 'hack'.

Why this score: The speaker is detailing the specific observation that led to their investigation: a TikTok badge appearing on a comment without an associated poll. This is a factual description of an anomaly they witnessed, serving as the premise for the 'exploit' story. No persuasive framing is present here.

Original quote: β€œYou know those badges, they show up when someone votes on a poll in the comments, except this video had no poll. The badge was just there saying whatever that person wanted it to say.”

Claiming a genuine security vulnerability confirmed by TikTok's team β€” Confidence Mismatch (45/100)

At 0:19

Says TikTok's team 'confirmed it, as you can see' β€” but we can't see anything yet. Just a bold assertion. 🚩

Why this score: The speaker confidently states that TikTok's security team confirmed the vulnerability, adding 'as you can see.' However, at this point in the video, no visual evidence (like a screenshot of communication with TikTok) is presented to support this claim. It's a strong assertion of external validation without immediate proof, creating a confidence mismatch between what's said and what's shown.

Original quote: β€œI thought that was pretty weird. So, I spent the night figuring out how it worked. Turns out it was a genuine security vulnerability. TikTok's own security team confirmed it, as you can see, and now this is that story.”

Describing Charles Proxy as a tool to expose app requests, making interception 'easy peasy'. β€” Confidence Mismatch (45/100)

At 0:30

Calling intercepting requests 'easy peasy' with Charles, right before showing it doesn't work. That's some serious foreshadowing. 🀑

Why this score: The speaker expresses high confidence that Charles Proxy will make intercepting requests 'easy peasy,' setting up an expectation that is immediately contradicted by the subsequent demonstration. This creates a mismatch between the stated confidence and the actual outcome, serving as a rhetorical device to build anticipation for the next step in the hacking process.

Original quote: β€œAnd what Charles does is it basically exposes what the app does under the hood. It shows you all of the things that that apps are requesting from their server in order to give you the information. And this would be amazing. It would help us a lot. We could like intercept the requests. It would be…”

Frida can bypass TikTok's security walls before they even load. β€” Confidence Mismatch (45/100)

At 2:30

Claiming to 'take down' security walls before they're 'put up' sounds a bit like a cartoon villain, but the core idea is plausible for a dev tool. πŸ¦Έβ€β™‚οΈ

Why this score: The speaker confidently states Frida can 'take down' TikTok's security walls before they're even active. While injecting before full load is a known technique for reverse engineering, the phrasing 'take them down' is a bit dramatic for what's essentially bypassing or observing, rather than actively 'dismantling' a fully-fledged defense system. It's a strong claim about the tool's power.

Original quote: β€œFor short, Frida is a tool that allows us to inject into TikTok before it loads and before they're able to put up their security walls, we can just take them down and read the requests as nothing ever happened.”

Claiming TikTok's server doesn't validate 'user vote info'. β€” Confidence Mismatch (45/100)

At 4:30

Claiming 'never checked' with such certainty is a bold move, especially for a security flaw. Show us the receipts! πŸ•΅οΈβ€β™‚οΈ

Why this score: The speaker asserts with high confidence that the 'user vote info' field is 'never checked on the server.' While they are demonstrating an exploit, stating 'never checked' is a strong, absolute claim about a system's internal workings without providing direct evidence of having audited the server-side code. It's a confident assertion that could be an oversimplification or an assumption based on observed behavior rather than definitive knowledge of TikTok's backend.

Original quote: β€œHowever, the user vote info is never checked on the server. So, you can put whatever you want in the user vote info. You can just inject it into any comment and TikTok's going to be like, "Oh, okay. I mean, I guess that TikTok just has a poll if you can have user vote info on it." Okay, so now that…”

Outro music with confident, self-congratulatory lyrics. β€” Just Vibes (50/100)

At 6:30

Ending with 'came in with the sauce' and 'play real raw' β€” that's just pure, unadulterated swagger. 🎀πŸ”₯

Why this score: This segment is the outro, featuring music with lyrics that are self-aggrandizing and celebratory. It's not a factual claim but rather an expression of confidence and a stylistic choice to end the video. It's pure entertainment and 'vibes' rather than a persuasive argument.

Original quote: β€œYeah, I came in [music] with the sauce. Oh, yeah, I came in with the sauce. Yeah, I play real raw. [music] Yeah, I play real raw.”

See the full analysis with timestamps β†’