X Money Security Strained By Coordinated Password Reset Wave Targeting Crypto Users

Generated byAinvest Coin BuzzReviewed byThe Newsroom
Thursday, Sep 3, 2026 9:47 am ET3min read
USDC--
Aime RobotAime Summary

- X investigates password reset attacks targeting crypto influencers and CoinDesk staff amid X Money's U.S. launch, with DOJ collaborating to track cybercriminals.

- Security experts attribute the surge to credential stuffing from historical data leaks, not a direct X system breach, as attackers exploit X Money's financial value for compromised accounts.

- X confirms no system breach but warns of risks linking financial services to social media865139--, urging users to enable two-factor authentication and Password Reset Protection.

- The incident highlights vulnerabilities from past API flaws and phishing campaigns, testing trust in X's expanding financial infrastructure as it integrates stablecoins and payment services861277--.

On September 1, 2026, X experienced a significant surge in unsolicited password reset emails, with thousands of users receiving up to ten reset requests within a few hours . The incident prominently affected prominent crypto figures and CoinDesk employees, raising immediate security concerns within the digital asset community. X Product Engineering team member Mridul Singhai confirmed the company is actively investigating the incident but has found no evidence of a system breach to date . The timing of the attack is notable, occurring just one day after X Money was rolled out to all U.S. Premium and Premium+ subscribers .

Why Are Crypto Accounts Being Targeted Now?

The wave of reset requests coincides with the expansion of X Money to Premium and Premium+ subscribers in the United States . The payment service, developed with Cross River Bank, offers deposit accounts, instant transfers, and a Visa debit card with up to 6% annual yield on deposits . X stated that attackers appear to believe the availability of X Money increases the value of compromised accounts for financial gain . The service allows users to send money directly via the platform, turning social media profiles into potential financial targets.

Beyond peer-to-peer transfers, X is reportedly considering the integration of USDCUSDC-- and other stablecoins for creator rewards . Although no specific token or launch date has been confirmed, the current service remains limited to U.S. subscribers and does not yet support cryptocurrency transactions . Funds are held at FDIC-member banks, with pass-through insurance covering up to $10 million for eligible customers . This expansion underscores the platform's shift from a social network to a financial infrastructure provider, attracting heightened attention from malicious actors .

What Is The Source Of The Reset Emails?

Security experts advise users to verify sender addresses and enable two-factor authentication to mitigate such attempts . The reset emails are generated by X’s own systems when accounts are flagged as compromised or targeted, triggering proactive security alerts for legitimate users . Researchers attribute the activity to a combination of legacy vulnerabilities and active external attacks rather than a new direct platform breach . A 2021-2022 API flaw allowed mapping email addresses to accounts, compounding risks from a 2025 dataset of 201 million records .

Breakglass Intelligence identified an unsecured command-and-control panel in April 2026 running stolen credentials against X accounts . The panel confirmed 18 new compromises out of 4.8 million attempts, highlighting the scale of automated credential stuffing operations . Additionally, a phishing campaign targeting X users since July sends emails mimicking new device login alerts to steal credentials . A separate service disruption at Proton, caused by hardware failure, may delay email delivery for users relying on that inbox but is unrelated to the security events .

How Is The U.S. Government Responding?

The U.S. Justice Department is actively working with Elon Musk’s X to identify and track down the perpetrators behind the recent attack . U.S. Attorney General Todd Blanche described the incident as an attempt by sophisticated cyber criminals to gain unauthorized access through the account-recovery process . Blanche stated on X that the platform successfully disrupted the attack, though he declined to provide further operational details . This event occurs against a backdrop of increasing global concerns regarding AI-driven cyberattacks and ransomware .

In response to these rising threats, the White House launched a coordination group in July to facilitate information sharing between AI developers and critical infrastructure operators . X advises users to enable Password Reset Protection and two-factor authentication to prevent unauthorized access . The platform clarified that reset codes are valid for 60 minutes and that legitimate emails will never ask for passwords . This incident follows a 2023 data leak involving 200 million X accounts, raising concerns about the platform's ability to secure user data as it expands into digital payments .

While no credentials have been stolen, the incident highlights security risks associated with linking financial services to social platforms . The crypto community is demanding greater transparency regarding X Money's security protocols and the effectiveness of its defenses . Experts recommend activating Password Reset Protection and switching two-factor authentication to authenticator apps immediately . The event serves as a critical trust test for Elon Musk’s payment infrastructure as it integrates deeper into the financial ecosystem .

Blending traditional trading wisdom with cutting-edge cryptocurrency insights.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet