X Money has barely begun rolling out, and attackers are already testing another way into X accounts.
Several users have reported receiving repeated, unsolicited password-reset emails from X following the launch of the platform’s new payments service. The messages themselves appear to be legitimate X security emails triggered through the company’s account-recovery process.
The concern is what comes next. Attackers may be able to use a public X username to generate repeated reset requests, then exploit the resulting confusion with phishing messages designed to steal login credentials.
Because X Money adds financial services to the platform, a compromised account could potentially become more valuable to attackers. However, there is currently no confirmed evidence in the draft that these reset attempts have led to successful account takeovers.
That means the attackers do not necessarily need to know a user’s email address or password to start the process. That reset flood also created an opening for phishing, according to user reports cited by Euronews.
The logic is that after receiving genuine X security emails, a user may be more likely to trust a follow-up message claiming that their account needs to be secured or reset. Such a message could then direct the victim to a fake X login page designed to steal their credentials.
The apparent end goal is account takeover because X Money provides those accounts with a payment that can fuel financial fraud. According to Euronews, the company’s embedded chatbot, Grok, has responded to some of the reports, offering users practical steps to help secure their accounts.
While X has not officially acknowledged the issue or responded to TechCrunch’s request for more details, the company is aware of the incident. A product engineer at the company apologized for any inconvenience and notified users that the company is investigating the issue.
X threatens legal action against attackers
X has also signaled that it intends to pursue those responsible.
According to TechCrunch, the company’s legal counsel, James Burnham, has commented on the issue, vowing to prosecute those behind the act.
Burnham wrote on X, saying that “the legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off Earth who attempts to victimize our platform’s users.”
Whether you use X Money or not, here is what you should do
Because X now has a payment platform directly under it, the value of X accounts to threat actors has increased. The reports are a reminder that X users — particularly those who plan to use X Money — should treat account-security alerts and reset emails with extra caution.
Users should enable two-factor authentication so that a stolen password alone is less likely to give an attacker full access to the account.
Beyond that, users should watch for suspicious messages across the platform. That includes unsolicited DMs, replies, or public X posts asking them to click a link, verify their account, reset a password, or provide personal or payment information.
Emails should receive the same scrutiny, particularly when they arrive unexpectedly or contain links asking users to sign in.
Most importantly, X Money changes how users should think about the security of their X accounts. An X account should no longer be treated simply as a place to post, follow people, and exchange messages. Once financial services are attached to the platform, users should apply the same security mindset they use with their banking apps.
That may include:
- Use a strong, unique password
- Enable two-factor authentication
- Secure the email account linked to X
- Review account activity regularly
- Install X and operating-system updates promptly
- Avoid signing in through links in unexpected emails or messages
That matters because today’s attack may involve abusing a legitimate password reset flow, but tomorrow’s could take a subtler or more sophisticated form. The safest approach is to secure the account before an attacker finds a new way to target it.
More news: CrowdStrike FalCon 2026 highlighted how autonomous AI is compressing cyberattack timelines, with security leaders warning that defenses must increasingly operate at machine speed.





