
Hijack Wave: Attackers Target X User Accounts Following X Money Launch
Attackers are targeting user accounts on X following the launch of X Money. Numerous platform members reported receiving unexpected password reset emails over recent days. A company representative confirmed that security teams are investigating the wave of reset requests, though investigators have found no evidence showing hackers successfully breached internal systems.
X product engineer Mridul Singhal posted an update on Tuesday confirming that internal teams are actively looking into user complaints regarding mass password reset alerts. Singhal explained that attackers likely believe the release of X Money creates a valuable target for account takeovers. He reassured members that security checks showed no evidence of compromised accounts or broken databases, while apologizing for the spam alerts landing in inbox feeds.
X Money rolled out as a digital payment service offering bank card integration alongside financial features. For platform creators, the tool offers a streamlined way to receive direct payments and payouts, expanding transaction options across the network. However, moving money through social platforms always attracts malicious actors looking to steal payment credentials or access stored account balances.
X general counsel James Burnham issued a warning regarding the malicious activity. Burnham stated that legal and security teams will track down, locate, and prosecute any bad actors attempting to compromise user accounts on the platform.
As the spam alerts spread, account owners are warning each other to tighten profile security settings. Power users urge members to turn on two-factor authentication immediately if they have not done so already.
X’s automated chatbot Grok also responded to user questions regarding the issue. Grok confirmed that attackers are mass-triggering public password reset forms by feeding public account usernames into automated scripts. The AI assistant confirmed that the attack relies entirely on external form requests rather than internal system breaches or database leaks.
To block incoming reset spam, X provides a built-in security feature called Password Reset Protect. Turning on this toggle forces the app to require verified email addresses or phone numbers before firing off reset links to a user’s inbox.
Social media networks regularly face automated credential stuffing and password spam when launching financial features. When platforms handle payment processing, securing user accounts requires strong authentication protocols. Users should update passwords, turn on multi-factor protection, and avoid clicking unverified email links landing in their inbox.







