X accounts were hit on Tuesday by password reset emails nobody asked for. One user’s inbox shows eight emails landing in three minutes. X says it has found no breach.
The emails are real, coming from X itself, not from fake senders. Attackers are pointing X’s own recovery form at public usernames, over and over.
BEWARE OF THIS!! ENABLE 2FA AND PASSWORD RESET PROTECT ON YOUR X ACCOUNTMany accounts are getting breached https://t.co/uy5pFsW9hB
— Sweep (@0xSweep) September 1, 2026
Follow us on X to get the latest news as it happens
X answered through Mridul Singhai, a product engineer at the company. He gave a motive, denied a breach, and apologized.
Attackers appear to believe that, now that XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience…,” wrote Singhai.
That was the company’s only word on it. The main X account, X Support, and X Money all stayed silent.
The motive fits the calendar. X Money began peer-to-peer payments for US Premium subscribers in late June. Deposits sit at Cross River Bank, with federal insurance of up to $10 million.
So an X login is now also a bank login. That changes the math. A stolen profile can promote a fake token. A stolen wallet can be emptied.
No leak has been confirmed. Attacks like this usually run on old email lists that circulate on criminal markets for years.
X’s recovery form accepts a username on its own. Usernames are public. That is the whole opening.
The fix already exists: X’s help pages tell anyone receiving resets they “did not request” to turn on Password reset protection. The form then demands the email or phone on file first.
Nikita Bier, formerly head of product at X, posted the toggle on Tuesday. His screenshot passed 85,000 views by the afternoon.
“Just turn this on,” Bier noted.
Two more layers help:
X has been here before, albeit from the inside. In July 2020, attackers talked their way past staff and reached an internal admin tool. They swapped confirmation emails and forced resets on 130 accounts, taking $118,000 in Bitcoin.
This time the attackers are outside, using a public form. The target has not changed. Neither has the advice on hardening X accounts.
Whether X rate-limits the form or leaves this to users is still open.