X probes wave of password reset attempts tied to X Money rollout

X is investigating a surge of unsolicited password reset emails following the launch of its payments service, X Money. A company engineer said attackers appear to be mass-triggering reset forms using public usernames, but no breaches have been confirmed so far. Users are being urged to enable two-factor authentication while the platform's legal team warns it will pursue those responsible.
The reset email wave began shortly after X Money's debut, a payments service offering a bank card and creator-focused payout features. X engineer Mridul Singhai publicly acknowledged the investigation, noting attackers appear to be exploiting publicly visible usernames to flood the password reset form, generating unsolicited emails for many accounts. The company's general counsel issued a stern warning about pursuing perpetrators.
No confirmed account takeovers or system breaches have been identified, according to both Singhai and X's Grok chatbot, which also advised users to enable Password Reset Protect. The incident highlights how new financial features can attract credential-stuffing and phishing attempts, even when the underlying platform remains secure.
This incident could erode user confidence in X Money at a critical launch moment, potentially slowing adoption of the payments feature. While no breaches are confirmed, the flood of reset emails may cause confusion and anxiety among users, some of whom could fall victim to lookalike phishing messages. The episode underscores how financial services on social platforms create new attack surfaces, affecting both everyday users and creators who depend on the platform for income.