X is investigating a surge of unsolicited password-reset emails that hit hundreds of thousands of users beginning September 1, coinciding with the wider rollout of its X Money payments service[1][5][13]. While the company and U.S. authorities describe the activity as a coordinated attempt to abuse X’s password recovery flow, both say there is no evidence so far that the platform was breached or that accounts and funds were successfully taken over[1][8][13].
Users first reported receiving multiple password-reset messages and six-digit codes within hours, all apparently sent from legitimate X infrastructure rather than spoofed domains[1][4][8]. In a post on X, product engineer Mridul Singhai said attackers “appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” adding that the company is “actively investigating” and has found “no evidence of any breaches” so far[5][12]. X’s Grok chatbot has replied to user threads noting that attackers are “mass-triggering” the password-reset form using public usernames, but reiterating that there is “no confirmed system breach or mass takeovers”[1][3].
The timing has focused attention on X Money, which offers eligible U.S. users an in-app financial service layer, including interest-bearing balances, a debit card, and peer-to-peer payments, making high-follower and business accounts more attractive targets[1][5]. Several reports indicate that prominent crypto traders and influencers were among those flooded with reset emails, amplifying concerns that attackers are singling out accounts with direct access to payments or strong social-engineering potential[2][4][10]. Attorney General Todd Blanche said on X that “hundreds of thousands” of users were affected and that the Justice Department is working closely with X to identify the groups behind the attack[8][13].
Despite the apparent link to X Money’s expansion, investigators and independent researchers caution that the reset wave may be riding on older exposure rather than a new zero-day flaw or undisclosed CVE in X’s infrastructure[6][9]. Multiple analyses tie the activity to historic Twitter data leaks and a 2025 dataset of roughly 200 million user records circulating on criminal forums, combined with credential-stuffing botnets and a phishing campaign that has mimicked genuine X login alerts since July 2026[6][9][15]. At this stage, neither X nor government agencies have published a vulnerability advisory, CVE identifier, or patch bulletin specific to the password-reset mechanism, reinforcing the view that the abuse stems from mass automation and legacy data rather than a fresh technical exploit[6][9][13].
The campaign hinges on a critical distinction: requesting a password reset is not the same as completing it, and neither automatically means a successful account takeover[5][11]. X’s recovery flow allows anyone to submit a public username into a form, but the reset link or code is delivered only to the email address or phone number already associated with that account, which an attacker must control to proceed[1][5][11]. Singhai and other X representatives have urged users to enable “Password Reset Protect” in their security settings, which forces the service to confirm stored contact details before sending reset messages, and to turn on two-factor authentication or passkeys to block logins even if a password is compromised[5][7][10].
For defenders, the attack’s main impact today is noise and confusion rather than confirmed compromise: repeated legitimate-looking resets can desensitize users to real alerts, pressure them into unnecessary password changes, or provide cover for phishing lures that closely imitate X’s genuine emails[5][6][15]. Similar tactics were seen earlier this year when Meta disclosed that an external actor abused Instagram’s reset mechanism to trigger large volumes of password emails without breaching core systems, underscoring that reset flooding is now a cross-platform nuisance and pretext for social engineering[14]. Security teams are advising X users to ignore unexpected reset links, verify account changes only by navigating directly to the app or site, maintain unique passwords, and treat any request for reset or two-factor codes—whether via email, direct message, or phone call—as a likely scam[5][7][15].
References
- X says attackers are targeting user accounts after …
- X: Crypto Accounts Targeted by a Reset Wave
- X Users Hit by Wave of Password Reset Attacks Amid …
- Musk’s X hit by wave of unsolicited password reset emails
- X Money is live, and now attackers appear to be eyeing X accounts
- Password Reset Issue on X: Thousands of Reports, But Is It an Attack? | WEEX Crypto News
- Hackers send unexpected password reset emails after X …
- US Justice Department puts hacker groups on alert after X cyber attack
- X Password Reset Issue Surges Despite No Confirmed Breach
- Wave of X password reset emails raises security concerns
- X Investigates Password-Reset Wave Following X Money Rollout
- Mridul Singhai on X
- US Justice Department pursuing hackers behind attack on X users
- Instagram Reset Email Surge Exposes Identity Blind Spots
- X Scammers Deploy ‘Near-Exact Replicas’ Of Legitimate …
