X Investigates Mass Password Reset Attacks Following X Money Launch
Attackers are triggering password reset emails in an apparent attempt to exploit the platform's new financial services.
X is investigating a widespread wave of unsolicited password reset emails targeting its users. The company believes these attempts are specifically timed to coincide with the rollout of X Money, its new integrated payments service.
According to reports from TechCrunch, attackers are mass-triggering password reset forms by utilizing public usernames. This tactic is designed to harass users or potentially trick them into granting unauthorized access to their accounts. Despite the volume of these requests, X has stated there is currently no evidence of a systemic breach or any successful mass account takeovers.
The Shift to Financial Services
This security incident follows the introduction of X Money, a strategic effort by the platform to build a comprehensive digital economy. The new service includes a bank card and various other benefits specifically designed to help creators collect payments more efficiently. By transforming from a social network into a financial hub, X has fundamentally changed the value proposition of a user account.
Historically, the introduction of financial capabilities and the movement of actual currency increase the incentive for bad actors to target a platform. When accounts are linked to bank cards and payment rails, they transition from being repositories of social data to potential gateways for financial theft.
Implications for Platform Trust
The timing of these attacks suggests that the addition of X Money has made user accounts significantly more attractive targets for hackers. If these attempts were to succeed, the consequences could extend beyond simple account hijacking to include identity fraud and direct financial theft. Such outcomes would severely undermine user trust in X's new payments infrastructure at a critical stage of its adoption.
Addressing the threat, X product engineer Mridul Singhai noted that attackers appear to believe they can gain unauthorized access now that X Money is widely available. The company has taken a hardline stance on the matter, with X general counsel James Burnham stating that the legal and security teams will work to identify and hold any individuals who attempt to victimize users criminally accountable.
Monitoring the Threat
While Grok, X's AI bot, confirmed the wave of unsolicited emails, the company maintains that the system itself remains secure. Users are encouraged to remain vigilant against phishing attempts that often follow mass password reset triggers.
Industry observers will be watching to see if X implements stricter rate-limiting on its password recovery tools to prevent this type of mass-triggering. For now, the primary concern remains whether this is a precursor to a more sophisticated attack or an opportunistic attempt to exploit the perceived vulnerability of a new financial rollout.