edit: from the responses looks like I was wrong; the urls still point to `carfatwitter.com`. Leaving my comment up in case others were confused like me.
edit: from the responses looks like I was wrong; the urls still point to `carfatwitter.com`. Leaving my comment up in case others were confused like me.
e.g "https://twitter.com/{acc}/status/{id}" -> "https://x.com/{acc}/status/{id}".
So if you post "https://carfatwitter.com/scam" it will be rewritten to "https://carfax.com/scam". Essentially search and replace of twitter.com -> x.com, 's/x.com/twitter.com/g'.
Note I have no direct experience with this, it's just the only way this makes sense as a phishing vector. The alternative is that it is being presented as a phishing vector, but was never actually useful as such, and people are just jumping up to yell about a security issue without it actually being one. That happens too.