Some accounts got ten password reset emails in a few hours. The targets weren’t random — crypto influencers, CoinDesk staff, accounts whose email addresses were public anywhere. X says no confirmed breach. Its own AI chatbot gave users the safety instructions before the company did.
Attackers launched a coordinated wave of password reset attempts against X users starting 1 September, days after X Money, the platform’s new payments service, expanded to all Premium and Premium+ subscribers in the US. Some users reported receiving up to ten unsolicited reset emails within a few hours. X product engineer Mridul Singhai confirmed the company was investigating: “Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorised access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches.” X’s own AI chatbot, Grok, replied to affected users with mitigation steps before the company’s official account did.
What’s Happening & Why It Matters
How the Attack Worked

The mechanism here is simpler and more mundane than a system breach, at least based on what’s confirmed so far. Grok described attackers “mass-triggering” X’s password reset form using available usernames — not exploiting a security flaw in X’s authentication system, but hammering the reset function against known account handles. That’s a unique threat compared to a database compromise. It’s noisy, disruptive, and alarming to receive, but it doesn’t, on its own, grant an attacker access to anything.
Grok was specific about the current state of evidence: “No confirmed system breach or mass takeovers.” That distinction — a flood of reset requests versus an actual account compromise — is the one X has repeated across every official statement. As TF covered when X Money launched nationally in July, the service added deposit accounts, a Visa-backed debit card, and peer-to-peer payments inside the app — features that make an X account more valuable to compromise than it was before X Money existed at all.
The Targeting Wasn’t Random

Here’s the detail that complicates X’s “mass-triggering” view. Reports indicate the wave concentrated on prominent crypto accounts. One trader reported an aggressive reset attempt against his profile despite having two-factor authentication already enabled. Several CoinDesk employees confirmed they’d been targeted too — notably, some of them using email addresses that were exposed anywhere, which runs counter to a random, username-scraping attack and suggests at least some coordination or targeted list-building behind the campaign.
That targeting pattern matters for how the industry should treat X’s “no evidence of breach” reassurance. A random, brute-force reset campaign against public usernames looks different from one concentrated on high-value crypto accounts with obscured contact information. The frequency and specificity Cointribune documented — thousands of accounts hit, several with well-protected email addresses — reads as more deliberate than X’s place suggests.
X’s Legal Threat, and What It Means
X general counsel James Burnham issued an aggressive public statement: “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimise our platform’s users.” That’s forceful language for an incident the company itself hasn’t confirmed produced any successful account compromise. This response reads either as concern about the threat or as a deliberate signal to attackers that X is treating even unsuccessful attempts with prosecutorial seriousness.

Meanwhile, X’s practical guidance to affected users centred on two specific tools: enabling two-factor authentication, and turning on a feature called Password Reset Protect, found under Settings and Privacy. Grok delivered that guidance in replies to individual users’ posts — an unusual customer-support role for a platform’s own AI chatbot to fill ahead of, rather than alongside, an official company statement.
TF Summary: What’s Next
X continues investigating the reset-attempt wave, with no confirmed evidence of successful account takeovers as of this writing. The company has not disclosed how many accounts were affected in total, or whether the targeting pattern toward crypto-focused users has been confirmed as deliberate rather than coincidental. No specific security enhancement to X Money itself has been announced beyond the general password-protection guidance issued to users.
MY FORECAST: Expect X to confirm at least some successful account compromises once the investigation concludes, given how financial services attract more persistent and better-resourced attackers than social media accounts alone ever did — a pattern TF has documented across every platform that’s added payment features this year. The crypto-account targeting deserves continued scrutiny; if that pattern holds up under closer investigation, it suggests attackers built a curated target list rather than triggering resets against public usernames, a more sophisticated operation than X’s current public view describes. Watch whether X mandates two-factor authentication for X Money users, rather than leaving it optional — a financial product carrying real balances shouldn’t rely on users opting into their own account security.
Related Stories
- X Money Launches. Can It Replace Your Bank?
- FBI: Hackers Targeted Water Utilities in at Least 7 States
- A Reverse Lookup Service Exposed Millions of People’s Faces

