X is investigating a wave of unsolicited password-reset requests hitting user accounts just as its X Money payments service becomes broadly available, with the company saying attackers may be targeting accounts because they now carry greater financial value.
Numerous users reported receiving password-reset emails they had not requested on Sept. 1, in some cases receiving several messages within minutes or as many as 10 over a few hours.
Mridul Singhai, a product engineer at X, publicly acknowledged the activity and said the company was investigating.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai said.
X had found no evidence of a breach at the time of his statement, he added, while apologizing to users receiving repeated emails.
That distinction is important. Receiving an unsolicited reset email does not itself mean an attacker has obtained a user’s password, gained access to the account or compromised X’s internal systems.
X’s own password-recovery documentation shows that someone can begin the reset process using an account’s public username, as well as an email address or phone number. X then sends a recovery message to the email address associated with that account.
Completing the reset requires access to the verification channel. X recommends enabling its separate Password Reset Protection setting, which forces a user requesting a reset to provide additional account information before the reset link or confirmation code is sent.
That means an attacker repeatedly entering public usernames could generate a large number of legitimate X password-reset emails without actually possessing the credentials needed to take over those accounts.
X has not disclosed how many users received the requests, identified who is behind them or said whether the activity is being generated through one coordinated campaign.
Reports spread particularly quickly among cryptocurrency users on X, where account compromises have historically been valuable to attackers because established profiles can be used to promote fraudulent tokens, phishing links and fake investment schemes.
The timing coincides closely with X Money’s broader rollout.
X Money said on Aug. 31 that the service was now available to all Premium and Premium+ subscribers with US accounts and directed eligible users to a Money tab inside X.
The service had started rolling out more broadly on July 27 following an earlier limited launch.
X Money puts financial functionality directly inside the social-media platform. Through its partnership with Cross River Bank, eligible users can hold money, send peer-to-peer payments and use an X-branded Visa debit card without leaving the X ecosystem.
Cross River described the July launch as the first US social-media platform to embed FDIC-insured interest-bearing accounts, a Visa card and broader payment functionality directly into the platform.
X’s current product page advertises an annual percentage yield of as much as 6% for eligible users, 3% cash back on qualifying X Card purchases and access to a deposit sweep programme that can provide aggregate FDIC pass-through coverage of as much as $10 million, subject to conditions.
X Payments itself is not a bank.
Cross River provides the underlying stored-value account, while X Payments acts as a service provider giving customers access to the financial account and payment services through X. The account terms require customers to have an X account, a verified US phone number and meet other eligibility requirements.
The structure helps explain why account security has become more important.
Historically, taking control of an X account primarily gave an attacker access to someone’s identity, followers, direct messages and ability to publish posts. An eligible X account can now also serve as the interface to a financial account and payment services.
There is currently no evidence that the latest password-reset campaign has allowed attackers to access those X Money balances.
TechCrunch reported that X had not confirmed successful compromises connected with the campaign, while X’s main corporate and support accounts had not published a detailed incident notice at the time.
X’s own security guidance recommends users employ unique passwords, enable two-factor authentication and activate Password Reset Protection. With the latter enabled, X requires the email address or phone number associated with the account before initiating recovery.
The company has not said whether it plans additional changes to its password-reset system, such as stronger rate limits, following the current wave.
X Money Changes the Economics of Hacking an X Account
The password-reset emails may turn out to be little more than automated harassment of X’s account-recovery system.
But their timing exposes a much bigger security change created by X Money.
X is combining two things that have traditionally carried very different risk profiles: a public social identity and access to money.
Before X Money, a high-value account could still be extremely lucrative to steal. A crypto founder with hundreds of thousands of followers, for example, could have a compromised profile used to push a phishing site or fraudulent token.
But the money generally sat somewhere else.
Now X is trying to make the social account itself the front door to banking and payments.
That changes an attacker’s calculation.
Even if X Money’s underlying funds remain protected by Cross River and additional authentication controls, an attacker has more reasons to test whether an X login can be compromised. A single account may contain a valuable audience, private communications, identity information and access to a payments interface.
The current campaign appears to illustrate that incentive almost immediately after broad availability.
There is also an architectural question for X.
Its password-recovery process was built when the consequences of anonymously entering someone’s public username were mostly inconvenience: the legitimate owner would receive a reset email they did not ask for.
Once the same identity is attached to financial services, even harmless-looking security friction becomes more consequential.
A stream of password-reset messages can also become useful to attackers without producing a direct technical breach. Repeated legitimate emails can condition users to click password-related links. A phishing message inserted into that noise could become harder to distinguish from the real alerts.
That is why X’s existing Password Reset Protection feature suddenly looks more important than a minor optional setting.
Two-factor authentication addresses the later stage of an account takeover. Password Reset Protection makes it harder to abuse the recovery process in the first place.
The episode also shows the security burden that comes with Elon Musk’s long-running plan to turn X into an “everything app.”
Adding financial products can increase engagement and make X harder for users to leave. The same integration creates a much more attractive target.
A social network can tolerate some account-recovery spam as an annoyance. A platform that wants customers to trust it with deposits, payments and a debit card has to treat the same behaviour as a financial-security problem.
Nothing disclosed so far indicates that X Money itself has been breached or that customer funds were stolen.
That is an important limit on the story.
But attackers do not have to succeed for their behaviour to reveal something useful. X says they appear to be targeting accounts because they believe X Money has made them worth more.
If that assessment is right, the first major security consequence of X’s move into financial services has arrived almost as quickly as the product itself.
