Highlights
- X users reported a major surge of unrequested password reset emails on September 1, part of a pattern running since early August.
- An X engineer said attackers appear to be targeting accounts now that X Money is widely available.
- A credential-stuffing botnet tested 722,763 credential pairs in 12 minutes in an April 2026 wave; two-factor authentication blocked 85.6% of attempts.
- X says it has found no evidence of a new systems breach but is investigating.
- Coin Bureau and other accounts urged users to enable 2FA and X's password-reset protection immediately.
X users began reporting a sharp spike in unsolicited password reset emails on September 1, 2026, with some accounts receiving as many as ten reset messages within a few hours. Wu Blockchain reported that multiple users suspected attackers were mass-triggering the reset process using public usernames, while Coin Bureau warned its followers of a broader wave of attempted account takeovers coinciding with the rollout of X Money, urging users to secure accounts with two-factor authentication and reset protection.
What Triggered the Wave
According to Decrypt, the activity traces back to repeated automated submissions to X's account-recovery form, which accepts a public username alone and generates a genuine reset email or SMS to whatever address or phone number is tied to that account. X product engineer Mridul Singhai said attackers appear to believe that, now that X Money is widely available, they can use this method to gain unauthorized access to accounts, describing the incident internally as a “major hack attempt.” X has said it has found no evidence that its systems were newly compromised, though the company is actively investigating.
A Pattern Built on Old Leaks
The reset wave is layered on top of several previously disclosed weaknesses. A 2022 API flaw exposed more than 200 million user records, and a 201-million-record dataset of X screen names, emails, and account-creation data surfaced on BreachForums in April 2025. Separately, a credential-stuffing botnet detected in April 2026 tested 722,763 credential pairs in just 12 minutes, confirming 138 account compromises out of 4.8 million attempts — a run that two-factor authentication blocked 85.6% of the time. Security researchers also flagged an active phishing campaign since July that mimics X's own login alerts with fake verification links, plus an unrelated Proton email disruption that has complicated account recovery for some users.
Why This Matters for X Money
The timing is what has crypto-adjacent accounts on alert: X Money is Elon Musk's push to turn X into a payments platform, and any credible pattern of account-takeover attempts around its launch raises the stakes well beyond a locked social media profile. A compromised account tied to a funded X Money balance is a materially different risk than a compromised account with no financial rails attached, which is why security-focused accounts like Coin Bureau moved quickly to broadcast hardening advice rather than treating this as a routine spam nuisance.
What to Watch Next
X has not set a timeline for concluding its investigation, and no user has yet publicly confirmed a financial loss tied to X Money specifically. The next signal to watch is whether X escalates its response — such as rate-limiting the recovery form or requiring additional verification for username-only reset requests — and whether any confirmed account compromises surface with funds attached. Security recommendations circulating in the wake of the wave include switching to an authenticator app for 2FA, enabling “password reset protect” in account settings, and verifying that any reset email genuinely originates from an @x.com or @e.x.com address.
FAQ
Why are X users getting password reset emails they didn't request?
Automated submissions to X's account-recovery form, which accepts just a public username, are generating genuine reset emails sent to whatever address or phone is tied to that account.
Is this connected to X Money?
An X engineer said attackers appear to be targeting accounts now that X Money is widely available, though X has found no evidence of a new systems breach.
Has X confirmed a data breach?
No. X says it is investigating but has found no evidence its systems were newly compromised as of September 1, 2026.
How can X users protect their accounts?
Security recommendations include enabling X’s “password reset protect” feature, switching to an authenticator app for two-factor authentication, and verifying that reset emails come from an official @x.com address.
