X is investigating a wave of unsolicited password reset emails hitting user accounts, which the company believes is connected to the recent rollout of X Money, its new payments service. As of the latest update, X says it has found no evidence that any accounts have actually been compromised.
What’s Happening
X product engineer Mridul Singhai confirmed the issue in a post on the platform Tuesday: “Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
X’s own AI chatbot, Grok, also responded to user reports about the issue, describing it as attackers “mass-triggering” the password reset form using publicly known usernames, rather than a confirmed breach of X’s systems. “No confirmed system breach or mass takeovers,” Grok wrote in one reply, while pointing affected users toward the platform’s Password Reset Protect feature.
What X Money Is
X Money is X’s newly launched payments service, which includes a bank card and other financial features. The service is designed to make it easier for creators to collect payments directly on the platform, expanding X’s push into becoming a broader digital economy rather than just a social network.
Why Attackers Are Targeting It Now
The timing lines up with a familiar pattern in cybersecurity: whenever a platform adds a financial component, it immediately becomes a more attractive target for account takeover attempts. Attackers appear to be betting that gaining access to an X account now carries more direct financial value than it did before X Money’s rollout, prompting the mass password reset attempts X is currently investigating.
X’s Response
X general counsel James Burnham posted a pointed warning in response to the incident: “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.” As of publication, X had not posted details about the incident from one of its official company accounts, and had not responded to a press inquiry about the matter.
What Users Are Doing in the Meantime
With no official company-wide guidance posted yet, users have been warning each other directly on the platform and encouraging others to enable two-factor authentication if they haven’t already. X’s Password Reset Protect feature, which adds an extra verification step before a password reset can be completed, is specifically designed to prevent the kind of mass-triggered reset attempts being reported.
Why It Matters
Even without a confirmed breach, a mass password-reset campaign targeting a platform immediately after it launches a payments feature is a useful signal for users to take seriously. Financial features tend to draw a different, more motivated class of attacker than standard social account takeovers, and the fact that X hasn’t yet issued an official company statement, more than a day into public reports, leaves users relying on individual engineers’ posts and Grok’s replies for guidance rather than a formal security notice.
What X Money Users Should Do
Given the active investigation, X users, particularly anyone who has signed up for X Money, should enable two-factor authentication if it isn’t already active, treat any unexpected password reset email with suspicion rather than assuming it’s routine, and use the Password Reset Protect setting under Settings and Privacy > Security to add an extra layer of protection against exactly this kind of mass-triggered attack.
For continuing coverage of platform security incidents and the latest on X’s expansion into payments, keep following Tech News Reports for ongoing updates.

