Thousands of X users received password reset emails on Tuesday that they never asked for, with some accounts taking as many as ten within hours. High-profile crypto accounts are among the targets, including ones with two-factor authentication switched on. The platform says it is investigating and has found no evidence of a breach. The wave lands as X Money rolls out across the United States.
Key Takeaways
- Crypto accounts report up to ten password reset emails inside a few hours
- The recovery form accepts a plain username to trigger the email
- X says it has found no evidence its systems were compromised
Ten Emails in a Few Hours on a Single Account
The wave started on Tuesday. X users watched password reset emails they had never asked for land in their inbox, at a pace that turned worrying fast.
Some accounts took as many as ten emails within hours. Volume alone creates the problem. By the fifth one, a distracted user clicks, and that is precisely the behaviour this kind of campaign is built to produce.
The timing is not neutral either. X Money already covered 41 US states in June without offering a single digital asset, and the service has just opened to paying subscribers stateside. A social account wired to a payment layer no longer gets hijacked for the same reasons.
The target profile is anything but random. Crypto accounts followed by tens of thousands of people were hit, along with staff at specialist newsrooms. The targeting tracks audience value, not the luck of a mailing list.
One detail matters for anyone affected. Two-factor authentication stopped nothing here. It protects the final step, the login itself, and does not block a reset email triggered from outside.
Mridul Singhai, from the X Product Engineering team, wrote publicly that attackers appeared to believe that with X Money now broadly available, they could reach accounts without authorization. He added that the investigation was live and that no evidence of a breach had surfaced so far.
A Username Is Enough to Trigger the Send
The mechanic is more mundane than an intrusion. X account recovery lets anyone start a password reset from a username, an email address or a phone number.
When the request goes through the username, the platform sends the message to whatever address is tied to that account. The attacker therefore never needs to know it. A public handle and a script are enough to automate the request at scale.
That explains the absence of a server-side breach. Nothing was forced and no database leaked in this particular episode. A feature designed to help users recover an account was simply turned against them.
Customer data leaks feed campaigns like this one directly. Trezor let 13,689 customer addresses slip through its shipper in August, a file with no direct resale value but a perfect list for targeting identified holders.
So the real exposure sits in the inbox. Legitimate password reset emails and well-copied phishing ones look alike, and a user buried under notifications loses the ability to sort them quickly.
The line between nuisance and incident is thin. A reset only completes if the attacker gets hold of the link, which means getting into the mailbox itself. That address, often older and less protected than the social account, becomes the link worth watching.
The platform’s guidance comes down to two points. Turn on two-factor authentication and the password reset protection setting, then click no link inside any of those messages.
The 2023 precedent colours how this reads. Over 200 million X account records ended up on the dark web, pulled from an interface flaw dating back to 2021. Handle-to-email pairings have been circulating ever since.
Also on Cryptonomic:
- Crypto.com Halts Its Blockchain After a $75M Theft
- Chelsea Puts USDC on Its Premier League Shirt
- Trump Crypto Investors Lost at Least $4.7B
X Money Changes What a Hijacked Account Is Worth
Timing is the actual story. The wave lands as X Money deploys across the United States for Premium and Premium+ subscribers, a payments service built with Cross River Bank.
Until now, taking over a followed account meant posting a scam and hoping a few followers bit. With a payment layer attached to the same identity, the value of a hijacked account changes in kind. And reaction time is measured in minutes: a hardware wallet flaw drained $70M in bitcoin in forty-one minutes.
For anyone holding digital assets, the social account has become part of the security setup regardless. It works as public identity, as a contact channel with projects, and sometimes as a recovery point for other services. Tracing a thief still takes weeks of work, when the trail survives at all.
The profile of the targets adds a layer. A followed crypto account doubles as an announcement channel for projects, as proof of identity in funding conversations, sometimes as the only contact point with a community. Its value is not measured in followers but in what those followers are ready to believe.
In the near term, the question is whether the campaign converts into actual takeovers. A wave of failed attempts stays a nuisance. One genuinely hijacked high-reach account changes the accounting.
Over three to six months, the pressure moves onto the recovery function itself. A platform hosting a payments service cannot keep a form that accepts a public handle as its entry point. That is a product decision, and it now sits on a clock.
Follow the story on Cryptonomic.


