Have you ever scrolled through X, seen a blue checkmark or blue tick and thought: “this account must be legitimate”? That little blue badge still feels like a stamp of trust from the platform’s Twitter days. But is this really still the case and is the change clear enough for users?
This question is one of the main points of the European Commission’s decision to fine X under the Digital Services Act (DSA) for “dark patterns”. The DSA is designed to make online platforms safer and more transparent. The rules have made dark patterns – interface designs to deceive or manipulate users – illegal.
One badge, two meanings
On Twitter, the blue checkmark meant an account was verified. If you were looking to follow your favourite actor, singer or journalist, you might find ten accounts with the same name. The blue checkmark used to identify who was the real one. On X this has changed and anyone can get the badge by paying for X Premium.

Why is this a problem? Because while X changed the meaning of the badge, it did not change its appearance. And that is where many users get confused. The badge is still viewed as a sign of trust. In fact, this perception is so entrenched that X users still regularly call blue-checkmark accounts “verified users“.
The meaning of the badge may have changed, but the public’s reading of it did not.
A simple, cheap way into a complex algorithm
However, there is something more troubling than the badge’s meaning. Blue checkmark accounts seem to get systematically boosted by X’s algorithm regardless of whether the content is safe, accurate, or even legal. In fact, a meaningful share of those boosted accounts turns out to be unsafe for consumers, to say the least.
Scroll your main feed and you’ll likely find accounts promising “crypto is easy money,” or pushing investment schemes that don’t add up. Nearly all of them have the blue checkmark.
The cost of X premium is almost nothing compared to the money potential fraudsters can make with a successful scam. With a subscription from $3 a month (in July 2026), they get amplified reach and the false credibility the badge still carries. The algorithm doesn’t distinguish between a verified institution or public figure and a crypto scammer paying the same fee.
The badge that once required documentation now requires a credit card.
The badge alone isn’t really the only danger. It’s what the algorithm does with it.

Facilitating scams’ expansion
Here is where the EU’s DSA comes in. The law requires large platforms like X to identify the risks their services create, including those from a platform’s recommender systems which determines what suggested content is shown to users, and to take proportionate measures to reduce any risks. It also requires platforms to remove illegal content and accounts once they’re made aware of them and sets clear rules around adverts’ transparency.
Unfortunately, on X questionable content is often hidden as a ‘regular post’. Still, when a blue checkmark or tick is for sale, and content from these accounts get boosted, these are not regular posts anymore. They can be considered promotional content that should have an ad disclosure.
However, as X treats these posts as ‘organic content’, they don’t appear in X’s ad library, a tool also required by the DSA to increase transparency. These libraries should allow users to see who’s paying to reach whom, and with what content.
And this is where the two problems meet. If dangerous posts from premium accounts are not labelled as ads, they do not have to follow the rules that apply to ads. And because the repository doesn’t really work either, there’s no way to check any of this from the outside.
Where does it leave the users?
X has built a badge that looks trustworthy but isn’t. A recommender system that amplifies without checking what is being amplified.
Scam accounts figured that out fast. Until X closes that gap, the checkmark will keep reducing users’ trust and function as a tool that bad actors can “rent by the month”.
So, what can you do? Make sure you always pay attention, verify the account yourself before acting and flag content you think could be a scam.
Also, be aware that scams are not limited to X. BEUC recently filed a complaint against Meta, TikTok and Google for failing to protect consumers against financial scams.
The Commission’s fine on X is a step in the right direction, as well as the investigation into Grok and X’s recommender systems. But until X closes the gap, we’re each other’s best defence.
