Technology
X Says Attackers Are Targeting User Accounts After X Money Launch
X is investigating a surge of unsolicited password-reset emails after the wider launch of X Money. Users across the platform, including well-known crypto accounts, reported getting messages they never requested. Some received several in a few minutes. Others reported as many as ten in a few hours.X product engineer Mridul Singhai said attackers appear to believe that, now that X Money is widely available, they can gain unauthorized access to accounts. He said the company is investigating and has so far found no evidence of any breaches. He apologized for the flood of emails.X’s own systems appear to be sending the messages. That is an important distinction. This does not look, at least so far, like a fake-domain phishing blast. It looks like outsiders repeatedly triggering X’s real account-recovery process using public usernames.The company and its Grok assistant have said there is no confirmed system breach and no confirmed wave of mass takeovers. That is the official line as of this writing. An investigation is still open.Why X Money Changes the StakesX Money is the platform’s payments product. After a limited start earlier this summer, it became more widely available to U.S. Premium and Premium+ subscribers. Users can send money through X. Banking infrastructure is provided by Cross River Bank. X Money itself is not a bank. Deposits tied to the service sit with the partner bank.That product shift changes what an X login is worth. For years, a stolen X account was mainly useful for scams, impersonation, and spam. A login that can also move money is a different target. Singhai’s post made that motive explicit. Attackers, he said, seem to think the payments rollout made accounts more valuable to seize.There is still no public evidence that X Money itself was compromised, or that funds were taken through this reset wave. The concern is one step earlier: if someone controls the social account, the financial features attached to it become easier to abuse.Chief Legal Officer James Burnham said legal and security teams would pursue people trying to harm users. That is a warning. It is not a substitute for account locks and better recovery controls.What Users Are SeeingThe pattern is repetitive. A user who did not ask for a new password finds genuine-looking reset mail from X. Sometimes a code or login alert follows. Inboxes fill up. People worry they are already locked out or that someone is inside.Because the mail comes from X, the usual advice — “check the sender” — is less comforting than in a classic spoof. The danger is not only a fake link. The danger is also fatigue. After the fifth reset notice, a tired user may click something they should ignore or approve a prompt they did not start.Crypto-facing accounts were among the first to flag the wave in public. That is not proof they were the only targets. It is proof they noticed quickly, because those accounts have been hijacked for years to push fake giveaways and wallet drains. A payments layer on the same platform raises the same old fear in a new wrapper.Not the Same Thing as a Platform HackX is drawing a line between noisy recovery abuse and a broken backend.A platform breach would mean attackers got into X’s servers or user databases. The company says it has not found that. A recovery-form abuse campaign means anyone who can see a username can ask X to send a reset email, over and over. That can annoy millions of people without ever guessing a password.Both can be serious. They are not the same incident. The first is a company failure at the core. The second is often a product-design failure: a public identifier plus an email trigger with too little friction.If X’s current account is right, the attackers did not need to break the vault. They used a doorbell that anyone can ring.That still matters. Recovery email is how many takeovers begin when combined with inbox access, recycled passwords, or social engineering. A burst of real reset mail can also be cover for a later fake message that looks identical.The Payments Problem Social Apps Keep RediscoveringEvery network that adds money inherits bank-like enemies without always inheriting bank-like controls.Venmo, Cash App, PayPal, and crypto exchanges learned this the hard way. Once a username is a payment handle, account security is no longer a content-moderation problem. It is a consumer-finance problem. Regulators notice. So do thieves.X has spent years fighting hijacked profiles used for crypto scams. It has tried locks, labels, and extra checks when an account suddenly starts talking about tokens. X Money raises the ceiling. If the social graph and the wallet live in one app, a takeover is both a reputation event and a possible cash event.Users should treat an X account with Money enabled more like an online banking login than like a throwaway social profile. That means a unique password, two-factor authentication that is not SMS if a stronger option exists, and X’s “Password reset protect” setting, which is designed to block username-only reset attempts.Do not tap links in unexpected reset mail. Open the app or the official site yourself. If you did not start a reset, you do not need to finish one.What X Still Has to ProveAn apology and an investigation are the minimum. Users will judge the company on three things.First, can it stop the reset spam without locking legitimate people out? Rate limits, extra confirmation, and reset-protect defaults would do more than another post from an engineer.Second, can it show that no cluster of accounts actually changed hands? “No evidence so far” is not the same as “we checked every Money-enabled account.” Silence from the main support channels did not help on day one.Third, can it separate social lockouts from money lockouts in a way customers understand? People will tolerate a frozen feed more readily than frozen funds. X’s own product rules already warn that unusual activity or policy violations can restrict Money. Ambiguity there is how support crises start.The company also has a credibility problem that predates this week. Critics have argued for months that X should not handle payments given its record on scams and account abuse. A reset storm on the heels of a Money expansion is exactly the headline those critics expected.What This Means for X MoneyProduct launches attract attackers the way new ATMs attract skimmers. That is normal. What is not normal is treating the attraction as a surprise.If X wants Money to feel safe, recovery has to be boring. One email when you ask. None when you do not. A clear in-app banner when someone tries. Fast human review when a high-value account starts throwing alerts.Cross River Bank’s role does not automatically protect the social layer. Bank-held deposits can still be exposed if the front door — the X login — is weak. Users should remember which company they log into and which company holds the cash. They are not always the same.There is a competitive angle too. Apple, Google, PayPal, and the card networks sell trust as much as they sell rails. X is trying to attach money to a product famous for speed and fights. Speed is a feature in posting. It is a bug in account recovery.A Familiar Warning in a New ProductThe useful conclusion is simple and unexciting.X says attackers are targeting accounts because Money made those accounts look more like wallets. X also says the campaign has not been shown to succeed at scale. Users should act as if both statements can be true at once. The motive is real. The breach, so far, is not proven. The inbox noise is already here.
Comments (0)
Please log in to comment
No comments yet. Be the first!