The launch of X Money appears to have brought a new security concern for users, with attackers targeting accounts through a wave of password reset requests.
Several X users have reported receiving password reset emails they did not request. X says it is investigating the activity, but so far has not found evidence that the attempts resulted in successful account takeovers or a breach of its systems.
X product engineer Mridul Singhai addressed the issue on Tuesday, saying the company was aware of the reports and was looking into the sudden surge in reset requests.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” Singhai said in a post on X. He added that the company had found “no evidence of any breaches” so far and apologized to users for the repeated emails.
READ: Elon Musk’s X gets new lease on life with $1 billion equity (March 20, 2025)
The timing has raised concerns because X Money, the platform’s newly launched payments service, gives users access to financial features including a bank card. The service is also designed to expand the ways creators and other users can receive and move money through X.
That financial component could make X accounts a more attractive target for cybercriminals. X appears to believe the password reset campaign may be linked to attempts to gain access to accounts now that X Money is more widely available.
X general counsel James Burnham also weighed in, warning that the company’s legal and security teams would pursue those behind the attacks.
“The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users,” Burnham said.
READ: Goldman Sachs, Bank of America and 19 banks plan dollar stablecoin for 2027 (September 1, 2026)
Meanwhile, users have been sharing warnings about the suspicious emails and urging others to turn on two-factor authentication. The additional security measure can make it harder for attackers to access an account even if they manage to obtain a password.
Grok, X’s AI chatbot, has also responded to some users asking about the incident. It said attackers were “mass-triggering” password reset forms using publicly available usernames.
Importantly, there is still no confirmed evidence of a mass account takeover. Grok said there was no confirmed system breach or widespread takeover of accounts.
For now, the incident appears to involve an aggressive wave of password reset attempts rather than a confirmed compromise of X’s systems. Still, with X increasingly moving into payments, the security of user accounts is likely to face greater scrutiny as more financial activity moves onto the platform.


