X is investigating a wave of unsolicited password-reset requests hitting user accounts shortly after the wider rollout of X Money, its new payments service. Users have reported receiving repeated reset emails they never requested, in some cases several within minutes, raising immediate concerns about attempted account takeovers.

So far, however, X says it has found no evidence that its systems have been breached or that the reset campaign has resulted in widespread account takeovers. The activity appears to involve attackers repeatedly triggering X's legitimate password-recovery process rather than directly stealing passwords from the platform.

Users Report Repeated Reset Emails

Reports began spreading across X on September 1 as users posted screenshots showing multiple password-reset emails arriving in rapid succession. Some users said they received as many as 10 requests within a few hours, while others reported unexpected verification codes and security notifications.

The volume of messages naturally led some people to suspect that their accounts, passwords or email addresses had already been compromised. That is not what the available evidence currently shows.

X allows a password-reset request to begin with a public username. Once someone enters that username into the recovery system, X can send a legitimate reset message to the email address connected with the account. An attacker therefore does not necessarily need to know the victim's email address to trigger the message. That distinction helps explain why users are receiving authentic-looking emails from X without having initiated the process themselves.

X Says It Has Found No Breach

Mridul Singhai, who works on X's product engineering team, publicly acknowledged the issue and said the company was investigating the unusual activity.

“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai wrote. He added that X had so far “found no evidence of any breaches,” while apologizing to users for the repeated emails.

That remains the most important detail for users concerned that the reset campaign proves X has suffered another major data leak. As of September 2, there is no confirmed evidence that the current activity resulted from attackers gaining access to X's internal systems or obtaining users' passwords.

Reports from people receiving the messages also do not by themselves prove that an account was successfully compromised. The reset request still requires additional steps before a password can actually be changed.

Why X Money Changes the Stakes

The timing has attracted particular attention because X is expanding from a social network into financial services. X Money recently became available to Premium and Premium+ subscribers with US accounts. In its rollout announcement, the company said users could “open the Money tab in your sidebar to get started.”

The service is designed to allow eligible users to send money through X, adding a financial layer to accounts that previously centered mainly on posts, messages, creator activity and identity.

That potentially increases the value of compromising an X account. A stolen social account has long been useful for impersonation, scams, cryptocurrency fraud and hijacking established audiences. If financial functionality becomes connected to those same accounts, attackers have another reason to probe account-recovery systems and look for weak security practices.

X itself has linked the current activity to attackers apparently believing accounts have become more valuable following X Money's wider availability, although the company has not publicly detailed who is behind the campaign or how many users have been targeted.

Crypto Accounts Among Those Hit

The incident has been especially noticeable within the cryptocurrency community, where X remains an important channel for announcements, market commentary and communication between projects, investors and traders.

Several crypto-linked accounts reported receiving unexpected reset attempts, and multiple journalists also said they received similar messages. At least four staff members at one cryptocurrency publication received reset emails during the wave, according to its reporting.

Crypto investor Nic Carter was among those warning users about the activity, writing that “a lot of people” appeared to be receiving unsolicited reset attempts.

Crypto accounts are particularly attractive takeover targets because established profiles can carry significant trust. Attackers who successfully hijack one can potentially use its reputation to promote fraudulent tokens, fake investment opportunities, malicious links or impersonation campaigns.

There is currently no evidence that the present reset wave has produced widespread successful takeovers of that kind.

Password Reset Protection Becomes Important

X already provides a setting specifically designed to make unauthorized password-reset requests harder. Its Password Reset Protection option requires someone requesting a reset to provide additional account information, such as the associated email address or phone number, instead of relying only on a public username.

X's own security guidance recommends enabling that setting alongside two-factor authentication. The platform supports authentication through text messages, authentication apps and security keys, although available methods can depend on the user's account and subscription.

Two-factor authentication does not necessarily stop someone from generating a password-reset email, but it creates another barrier against an attacker trying to complete an unauthorized login.

Users receiving unexpected reset requests should also avoid assuming every future security email is legitimate. A flood of genuine reset messages can create an opportunity for separate phishing attempts designed to look similar.

X recommends checking that login pages use the genuine x.com domain before entering credentials and warns users against providing passwords through suspicious links or third-party services.

X Faces a New Security Challenge

The episode highlights a broader challenge created by X's push to combine social networking, creator monetization and payments inside one account. A social-media password used to protect posts, private messages and an online identity. Once the same account becomes tied more closely to financial activity, the consequences of losing access become potentially more serious.

That makes account recovery itself a more attractive target. For now, X's investigation has not produced evidence of a system breach, and the reset messages appear consistent with attackers abusing a public-facing recovery mechanism rather than directly obtaining user passwords.

But the timing offers an early indication of what X may face as X Money expands. Turning a social account into something closer to a financial identity also means convincing users that the security protecting that identity can withstand increased attention from attackers. Until X provides more detail about the campaign, users receiving unexplained reset emails should treat them as a warning to review account security rather than as proof that their account has already been hacked.

Comments