X accounts were targeted on Tuesday by a wave of unsolicited password reset emails. Some users reported receiving multiple emails within minutes, with one account showing eight reset requests in three minutes. The emails originated from X's legitimate systems, not spoofed senders.
The attack exploited X's password recovery form, which accepts usernames as the sole initial identifier. Since usernames are public information, attackers were able to repeatedly submit them to trigger reset emails.
X acknowledged the incident through Mridul Singhai, a product engineer at the company. "Attackers appear to believe that, now that XMoney is widely available, they can gain unauthorized access to accounts," Singhai wrote. "We are actively investigating the issue and, so far, have found no evidence of any breaches." The company apologized for the multiple emails but provided no additional public statements through its main accounts.
The timing aligns with X Money, the platform's peer-to-peer payments service for US Premium subscribers, which launched in late June. User deposits are held at Cross River Bank with federal insurance of up to $10 million, making account compromise potentially more valuable to attackers.
User Protection Measures
X's help pages recommend enabling Password Reset Protection, which requires users to verify their email or phone number before processing a reset request. The feature gained visibility after Nikita Bier, formerly head of product at X, posted instructions on Tuesday, which accumulated over 85,000 views.
Security experts recommend additional protections:
- Using an authenticator app instead of text message-based two-factor authentication
- Adding a passkey, which ties login access to a physical device
- Ignoring unsolicited emails, as fraudulent 2FA prompts have previously been used to drain cryptocurrency wallets
X experienced a similar attack in July 2020 when external attackers manipulated employees to access internal systems, ultimately compromising 130 accounts and stealing $118,000 in Bitcoin. The current attack operates through publicly available forms rather than internal access, but targets the same objective: account takeover.
It remains unclear whether X will implement rate-limiting on its recovery form to prevent future automated attacks of this nature.


