Highlights

  • The US Department of Justice is investigating a coordinated password-recovery attack that hit hundreds of thousands of X accounts on September 1, 2026.
  • Some users received up to 10 unsolicited password-reset emails within hours, with several prominent crypto figures among the targets.
  • The attack landed one day after X Money's wider rollout to Premium and Premium+ subscribers in the US.
  • X says it has found no evidence of a confirmed breach and disrupted the attempt before any accounts were hijacked.

US Attorney General Todd Blanche said on September 3 that the Department of Justice is working with X to identify the people behind a coordinated password-recovery attack that targeted hundreds of thousands of accounts on the platform this week. Blanche described the perpetrators as “sophisticated cyber criminals” and said X disrupted the attempt before attackers could seize control of any profiles. The incident, which unfolded on September 1, coincided with the wider US rollout of X Money and swept up a number of high-profile crypto accounts.

A Coordinated Wave of Password Resets

The attack took the form of mass “forgot password” requests rather than a direct exploit, according to a report on Blanche's statement. Some users said they received as many as 10 unsolicited reset emails within a span of a few hours — a pattern investigators say points to deliberate coordination rather than a technical glitch. Blanche declined to detail how the attackers operated or how many accounts were ultimately affected, but he confirmed the Justice Department is now working alongside X's security team to trace the source. The episode is the latest in a string of large-scale credential-stuffing and account-recovery attempts that have hit major platforms this year.

Crypto Accounts in the Crosshairs

Crypto figures were disproportionately represented among those who flagged the activity. Investor and analyst Nic Carter was among the first to warn the crypto community, while trader cap.eth reported aggressive reset attempts despite having two-factor authentication enabled, and multiple CoinDesk staff said they were targeted on email addresses rarely exposed publicly, according to Cointribune's account of the incident. X's Mridul Singhai of the Product Engineering team said the company has “found no evidence of breach” so far, adding that attackers “seem to believe that now that X Money is widely available, they can access accounts without authorization.” The concentration of crypto-linked targets has fueled speculation that the attack targeted accounts likely to hold linked payment credentials rather than sweeping the user base at random.

Related: Fake GTA 6 'Leak' Site Is Actually a Multi-Chain Wallet Drainer

X Money's Timing Raises Questions

The attack's timing is difficult to separate from X Money's expansion. The peer-to-peer payments product, which lets US Premium and Premium+ subscribers send and hold funds directly inside the app, widened its rollout on August 31 — one day before the reset wave began, as PANews reported. For an industry that treats X as its default newswire, where a single hijacked account with a large following has repeatedly been used to push fake token launches and phishing links, an attack that specifically clustered around crypto-adjacent accounts is a reminder that the platform's growing role in payments raises the value of any account it protects. Even a disrupted attempt underscores how thin the margin is between a foiled password-reset wave and a headline-making wallet-drain event.

What Comes Next

Blanche has not set a timeline for the investigation, and neither the Justice Department nor X has named a suspect or confirmed the attackers' origin. X says it is continuing to monitor account activity for signs of compromise following the X Money rollout, and the crypto accounts that flagged the activity have urged others to double-check recovery email addresses and enable hardware-based two-factor authentication rather than SMS. Any formal DOJ findings, or a follow-up statement narrowing down the attackers' identity or method, would be the next concrete marker in a case that, for now, remains an open investigation with no confirmed breach.

FAQ

What is a password-recovery attack?
It's an attempt to hijack an account by triggering or exploiting the “forgot password” process instead of guessing a password directly, often through mass automated reset requests.

Were any X accounts actually compromised?
X says it has found no evidence of a confirmed breach and that the attempt was disrupted before attackers could take over any profiles.

Why were crypto accounts targeted?
The wave hit shortly after X Money's wider rollout to Premium and Premium+ subscribers, and multiple crypto figures reported unusual reset activity, suggesting attackers may have been probing accounts with financial ties to the platform.

Who is investigating the attack?
The US Department of Justice, under Attorney General Todd Blanche, is working with X's security team to identify the people behind the attack.