· via TechCrunch
X investigates mass password reset attempts after X Money launch
X users are being hit by waves of unsolicited password reset emails after the launch of X Money, with attackers mass-triggering reset forms using public usernames. X says it has found no evidence of successful breaches.

What happened
A wave of unsolicited password reset emails has hit X users since the platform launched X Money, its new payments service, according to TechCrunch. The complaints piled up quickly enough that X product engineer Mridul Singhai publicly addressed them on Tuesday, saying the company is investigating what looks like a coordinated attempt on user accounts.
"Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts," Singhai wrote. He said X had so far found no evidence that any break-ins succeeded, apologized for the repeated emails, and asked users for patience while the company works on a resolution.
How the attack works
The mechanism appears to be abuse of a routine account-recovery feature. According to TechCrunch, X's chatbot Grok, which has been replying to posts about the incident, said the attackers are "mass-triggering" the password reset form using public usernames. Because a reset request can be submitted for any visible handle, doing so at scale causes X to send reset emails to large numbers of users who never asked for one.
Grok also stated there was no confirmed system breach and no mass account takeovers. As of TechCrunch's reporting, the incident looks like large-scale misuse of a standard feature rather than a compromise of X's own systems. Even so, unsolicited reset emails are a familiar harassment and phishing vector: they can flood inboxes, create confusion, and provide cover for lookalike messages designed to steal credentials.
X's response
TechCrunch reports that X has not posted details about the incident to any of its official company accounts and had not responded to a press inquiry at the time of writing. The clearest public acknowledgments so far have come from individual staff.
X general counsel James Burnham took an aggressive tone in a post, saying the company's legal and security teams "will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users."
Users, meanwhile, have been warning one another and urging people to switch on two-factor authentication. Grok has echoed that advice in its replies, walking users through the steps and pointing to a "Password Reset Protect" option in the platform's security settings.
Why X Money changed the stakes
X Money is a newly launched payments service that includes a bank card and other benefits, according to TechCrunch. The company's pitch is that it will make it easier for creators to collect payments on the platform, deepening what X calls its digital economy.
That financial layer appears to be exactly what drew the attackers. As TechCrunch notes, the arrival of money on a platform reliably attracts bad actors, and Singhai's own framing, that attackers believe accounts are now worth breaking into, points to the same conclusion. An account that once mattered mainly for posting is now, for many users, tied to a bank card.
Why it matters
The incident is a live example of how adding payments to a consumer platform changes its security calculus overnight. Features such as password reset forms, tolerable when an account's value was mostly reputational, become high-value targets the moment money is attached.
It also raises a preparedness question. Basic mitigations for reset-request abuse, such as rate limiting by submitting IP or by target account, or requiring extra verification before sending reset emails, are well understood, and the volume of complaints suggests the form could be triggered at scale with nothing more than public usernames.
For users, the practical takeaway is straightforward: enable two-factor authentication and any available reset-protection settings, and treat unsolicited password reset emails as noise rather than instructions. For X, the episode is an early stress test of whether it can secure a payments product before attackers find a variant of this attack that actually works.
- #x
- #security
- #x-money
- #payments
- #account-security
- #social-media