X Investigates Mass Password Reset Attempts Following X Money Launch
Quick Look
X is investigating mass password reset attempts targeting users after the launch of X Money, with no evidence of successful breaches found so far; users are advised to enable two-factor authentication as attackers exploit public usernames to trigger reset forms.
AI-generated summary
Why It Matters
X Money is X's newly launched payments service, which includes a bank card and other benefits, aiming to facilitate payments for creators on the platform.
Attackers are attempting to target X users following the launch of X Money. After numerous X users reported receiving unsolicited password reset emails, a representative said the social media company was actively investigating the issue but had not yet found evidence that the hacks were successful.
On Tuesday, X product engineer Mridul Singhai posted to the social network that the company was looking into users’ complaints about the mass password reset attempts.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” he wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
X Money is X’s newly launched payments service, which includes a bank card and other benefits. For X, the service could make it easier for creators to collect payments on the platform, further facilitating X’s digital economy.
Of course, money changing hands has a tendency to attract bad actors, which is what X says may be happening here.
X has not posted details to one of its official company accounts as of the time of writing, and has not yet responded to our press inquiry about the matter.
However, X general counsel James Burnham wrote a threatening post, saying, “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
As the attacks continue, users are warning each other about the problem and reminding others to enable two-factor authentication, if it’s not already enabled, to protect their accounts. X’s chatbot Grok has also replied to some posts with the steps on how to do so, while also confirming that the attackers are “mass-triggering” the form for password resets using public usernames.
“No confirmed system breach or mass takeovers,” the AI bot said.
Open Questions
- How many users were targeted in the password reset attempts?
- What specific methods are attackers using to mass-trigger password reset forms?
- Has X implemented additional security measures beyond user advisories?







