X Money Launch Triggers Account Attack Wave as Password Reset Attempts Surge

· · Views: 2,032 · 3 min time to read

X is investigating a wave of suspicious password-reset activity after the wider launch of X Money, highlighting how adding financial functionality can quickly change the security value of accounts on a social platform.

TechCrunch reported that numerous X users received unsolicited password-reset emails, prompting the company to investigate whether attackers were trying to gain unauthorized access. X product engineer Mridul Singhai said attackers appeared to believe accounts had become more attractive targets now that X Money was widely available, while stressing that the company had found no evidence of any breaches.

Attackers are probing the account recovery layer

The activity appears to be targeting one of the most common security surfaces on consumer platforms: account recovery.

TechCrunch reported that X’s chatbot Grok said attackers were “mass-triggering” password-reset requests using public usernames. Grok added that there was “no confirmed system breach or mass takeovers,” suggesting the flood of messages does not itself prove attackers successfully accessed accounts.

Mashable also highlighted the possibility that the password-reset wave could create an opening for a secondary phishing attack. Repeated legitimate-looking security notifications can make it harder for users to distinguish genuine account messages from fraudulent follow-ups designed to steal credentials.

CryptoRank advised users to avoid links in unsolicited emails and review their account security settings as the investigation continues.

X Money raises the stakes for account security

The timing matters because X is no longer positioning user accounts purely around social identity and content.

TechCrunch described X Money as a new payments service that includes a bank card and other benefits, with the product designed in part to make it easier for creators to collect payments through the platform.

That expansion alters the economics of account takeover. A compromised social account may already carry value through followers, identity and reach; attaching payments potentially gives attackers an additional financial incentive.

Singhai said X was actively investigating the incident and apologized for the multiple emails. Meanwhile, X general counsel James Burnham said the company’s legal and security teams would seek to identify and hold attackers criminally accountable.

Payments turn identity security into financial infrastructure

For product and security teams, the incident offers a broader lesson about fintech expansion.

Adding payments to an existing platform does not merely add another feature. It changes the threat model around authentication, password recovery, session security and identity verification because an account can suddenly represent both a digital identity and a financial asset.

X has not confirmed that X Money itself was compromised. But the attempted activity illustrates how quickly attackers can adapt when a platform introduces new economic incentives.

For companies pursuing “everything app” strategies, payments therefore make account security part of the financial infrastructure—not simply a supporting feature of the social product.

Share
f 𝕏 in
Copied