
X (Twitter) experienced a major password reset attack on Tuesday, with users receiving multiple unsolicited emails from the platform. According to reports from X, one user's inbox received eight emails in three minutes, all appearing legitimate as they came directly from X itself. The company has confirmed that the emails are real but emphasized they were not sent in response to any user requests, with attackers instead exploiting X's own recovery form system. As reported by BeInCrypto, the attackers are pointing X's own recovery form at public usernames, over and over, creating a systematic attack on the platform's recovery system.
X addressed the incident through Mridul Singhai, a product engineer at the company, who provided a detailed response to users. As reported by X, Singhai stated that attackers appear to believe they can gain unauthorized access to accounts now that XMoney is widely available. The company emphasized that it has found no evidence of any breaches and is actively investigating the issue. Singhai advised account holders to enable two-factor authentication and avoid opening links sent through unexpected emails. According to BeInCrypto, this was the company's only official response, with the main X account, X Support, and X Money all remaining silent during the incident. The company has not disclosed who may be responsible for the requests, how many accounts received them, or whether the activity came from an automated campaign.
The timing of the attack coincides with the recent launch of XMoney's peer-to-peer payments feature for US Premium subscribers, which began in late June 2025. According to X, deposits for XMoney are held at Cross River Bank with federal insurance of up to $10 million. This integration means that X login credentials now provide access to banking services, potentially increasing the value of stolen accounts for attackers. As reported by BeInCrypto, a stolen profile can promote a fake token, and a stolen wallet can be emptied, changing the mathematical value of compromised accounts significantly. The X Money service includes deposit accounts, instant transfers, and a Visa debit card with annual yields of up to 6% for eligible X Card purchases.
X has implemented existing security features that users can activate to prevent similar attacks. As reported by X, the platform's help pages instruct users receiving unsolicited resets to turn on password reset protection, which requires verification through email or phone on file before processing any requests. Additional security measures include using authenticator apps instead of text messages and adding passkeys that tie login to specific devices. Former X product head Nikita Bier shared screenshots of these settings, which received 85,000 views by afternoon on Tuesday. According to BeInCrypto, Bier noted that users should just turn this on and avoid leaving emails alone because fake 2FA prompts have drained crypto wallets before. X specifically advises users to check that login pages use the x.com domain and avoid clicking links from unexpected emails.
This incident represents a different type of attack compared to X's previous security breach in July 2020, when internal staff were compromised and 130 accounts were forced to reset with $118,000 in Bitcoin stolen. According to X, the current attackers are operating externally using public recovery forms rather than exploiting internal systems. The company has not yet confirmed whether it will implement rate-limiting measures on the recovery form or leave security enhancements to user activation. As reported by BeInCrypto, attacks like this usually run on old email lists that circulate on criminal markets for years, but X's recovery form accepts usernames on their own, making public usernames the primary opening for these systematic attacks.