Crypto news report · source clearly identified
X Reports Password‑Reset Spam Attack Targeting Users Amid X Money Rollout
X confirmed a surge of unsolicited password‑reset emails on Tuesday, attributing the activity to attackers exploiting the platform’s public username recovery form. No breach was detected, but users are urged to enable additional security measures.
On Tuesday, X users began receiving password‑reset emails they did not request. The messages originated from X’s own recovery system, not from spoofed senders, and were triggered by attackers repeatedly submitting public usernames to the platform’s password‑reset form.
Company response
Mridul Singhai, a product engineer at X, stated that the company has found no evidence of a breach and is investigating the incident. The statement was the only official comment; X Support and X Money accounts remained silent.
Possible motive
The timing coincides with the recent launch of X Money, a peer‑to‑peer payment service for U.S. Premium subscribers that stores deposits at Cross River Bank with federal insurance up to $10 million. Attackers appear to be attempting to gain unauthorized access to accounts that now also function as bank logins.
How the attack works
X’s recovery form accepts a username without additional verification. Because usernames are public, attackers can automate submissions, causing the platform to send password‑reset emails to the associated email addresses.
Recommended user safeguards
- Enable “Password reset protection” in X’s account settings, which requires the email or phone number on file before processing a reset request.
- Use an authenticator app instead of SMS for two‑factor authentication.
- Consider adding a passkey tied to a trusted device.
- Ignore unsolicited reset emails and do not click any links or enter credentials.
Historical context
In July 2020, attackers exploited an internal admin tool at X, forcing password resets on 130 accounts and stealing $118,000 in Bitcoin. The current incident differs in that the attackers are operating from outside the platform, using the public recovery form.
Open questions
It remains unclear whether X will implement rate‑limiting on the recovery form or rely solely on user‑enabled protections.
Source & attribution
News Source
- Publisher
- BeInCrypto
- Original date
- September 1, 2026, 4:11 PM
- Original headline
- X (Twitter) Alert: Major Password Reset Attack Breaks Out