X (Twitter) Alert: Major Password Reset Attack Breaks Out
X accounts were hit on Tuesday by password reset emails nobody asked for. One user’s inbox shows eight emails landing in three minutes. X says it has found no breach.
The emails are real, coming from X itself, not from fake senders. Attackers are pointing X’s own recovery form at public usernames, over and over.
Follow us on X to get the latest news as it happens
Major Hack Attempt on X
X answered through Mridul Singhai, a product engineer at the company. He gave a motive, denied a breach, and apologized.
Attackers appear to believe that, now that XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience…,” wrote Singhai.
That was the company’s only word on it. The main X account, X Support, and X Money all stayed silent.
The motive fits the calendar. X Money began peer-to-peer payments for US Premium subscribers in late June. Deposits sit at Cross River Bank, with federal insurance of up to $10 million.
So an X login is now also a bank login. That changes the math. A stolen profile can promote a fake token. A stolen wallet can be emptied.
No leak has been confirmed. Attacks like this usually run on old email lists that circulate on criminal markets for years.
How X Users Can Stop the Reset Spam
X’s recovery form accepts a username on its own. Usernames are public. That is the whole opening.
The fix already exists: X’s help pages tell anyone receiving resets they “did not request” to turn on Password reset protection. The form then demands the email or phone on file first.
Nikita Bier, formerly head of product at X, posted the toggle on Tuesday. His screenshot passed 85,000 views by the afternoon.
“Just turn this on,” Bier noted.
Two more layers help:
- Use an authenticator app rather than text messages, and add a passkey, which ties login to your device.
- Leave the emails alone, because fake 2FA prompts have drained crypto wallets before.
X has been here before, albeit from the inside. In July 2020, attackers talked their way past staff and reached an internal admin tool. They swapped confirmation emails and forced resets on 130 accounts, taking $118,000 in Bitcoin.
This time the attackers are outside, using a public form. The target has not changed. Neither has the advice on hardening X accounts.
Whether X rate-limits the form or leaves this to users is still open.
The post X (Twitter) Alert: Major Password Reset Attack Breaks Out appeared first on BeInCrypto.
Read more





