Cobo Agentic Wallet

X Investigates Account Attacks After X Money Launch Triggers Password Reset Emails

X is investigating a wave of unsolicited password-reset emails reported by users after the broad rollout of X Money. The company says attackers may be trying to access accounts because they now have payment functionality, but it has found no evidence so far that the attacks succeeded.

Cobo Newsroom
Cobo NewsroomSep 2, 2026
Key takeaways
  • Users reported receiving password-reset emails they did not request, raising concerns about attempted account takeover.
  • X product engineer Mridul Singhai said attackers may believe accounts are more valuable now that X Money is widely available.
  • X said it was actively investigating and had not found evidence of a successful breach or unauthorized access at the time of the report.
  • X Money includes a bank card and other payment-related features, potentially tying social accounts more closely to financial activity.
  • X had not published a detailed statement through one of its official company accounts or responded to the reported press inquiry.
  • The incident highlights the need to treat account recovery, identity verification and payment permissions as connected security controls.

News illustration

Summary

X is investigating a wave of unsolicited password-reset emails reported by users after the broad rollout of X Money. The company says attackers may be trying to access accounts because they now have payment functionality, but it has found no evidence so far that the attacks succeeded.

A wave of password-reset requests

X is investigating reports that users received multiple password-reset emails without initiating them, shortly after the broad availability of X Money. The incident has not been described as a confirmed account breach. Instead, the publicly reported facts point to a large number of attempts to trigger the platform’s account-recovery process.

According to information reported by TechCrunch, X product engineer Mridul Singhai said on September 1 that the company was looking into complaints about mass password-reset attempts. He wrote that attackers appeared to believe they could gain unauthorized access to accounts now that X Money was widely available. Singhai said X was actively investigating and had found no evidence of breaches at that point, while apologizing for the repeated emails.

That distinction is important. An unsolicited password-reset message can indicate that someone is trying to manipulate an account-recovery workflow, but it does not by itself show that an attacker knows the account password, has bypassed authentication, or has accessed payment information. The available reporting does not establish that any X account was successfully taken over.

Why the launch of X Money changes the risk profile

X Money is a newly launched payments service that includes a bank card and other benefits. X has positioned the service as part of a broader digital-economy strategy, including the possibility of making it easier for creators to receive payments on the platform. Linking a social account to payment features can increase the account’s practical value and, in turn, make account-access mechanisms more attractive targets.

A compromised social account can already be used for impersonation, spam, fraud or exposure of personal information. When the same account is connected to payment settings, a card or other financial functionality, attackers may also focus on account recovery, identity verification, linked contact details and device authorization. None of those potential risks means that X Money systems or user funds were affected in this incident; the source material does not report such an impact.

The key issue is the connection between identity and payment access. A payments product may have strong transaction controls, but attackers can still look for weaknesses in the surrounding account layer. Password resets, changes to an email address or phone number, customer-support recovery and the enrollment of a new device can all become relevant when a platform expands from social networking into payments.

What is known—and what remains unclear

X’s public response, as reported, is limited to the statement that an investigation is under way and that no evidence of a breach had been found. At the time of TechCrunch’s report, X had not posted detailed information through one of its official company accounts and had not responded to the publication’s inquiry.

As a result, several questions remain unanswered. It is not clear how many users received the messages, whether the activity was concentrated in a particular group of accounts or region, or whether the requests originated from a common automated campaign. The public information also does not identify the specific attack method or establish that X Money’s payment systems were directly involved.

Unsolicited reset emails can be generated by someone repeatedly submitting usernames or email addresses to a recovery form. They can also be used as part of a phishing campaign, in which a later message attempts to direct a user to a fraudulent page or to an impersonated support channel. However, the reported material does not confirm that the emails contained malicious links or that phishing was involved. It would therefore be premature to characterize the incident as a confirmed phishing operation or data breach.

The incomplete public picture also makes it difficult to assess the operational scope of the event. A high volume of reset requests may reflect an attack against the recovery interface, an attempt to create confusion among users, or a broader effort to identify active accounts. Determining the difference will require information from X’s logs, authentication systems and support operations.

Implications for payment-enabled platforms

The episode illustrates a broader security challenge for social platforms that add wallets, cards or payment capabilities. Account security becomes more than a question of protecting content and personal identity; it becomes part of the control environment for financial functionality. A platform must consider password-reset activity alongside failed logins, new devices, changes to recovery contacts and modifications to payment permissions.

For institutional wallet and custody operators, the same principle applies in a different operating environment: identity controls and asset-access controls should not be treated as interchangeable. Layered authentication, separation of administrative and transaction permissions, carefully controlled recovery procedures and auditable changes can reduce the chance that a compromised account becomes a path to broader authorization. These are general control considerations, not evidence that any particular provider was affected by the X incident.

Launch periods can make these controls especially important. A newly available service attracts additional users, new integrations and increased attention from both legitimate participants and malicious actors. Expanding access can also expose edge cases in onboarding, account recovery and customer-support workflows that were less visible during a limited rollout.

For users, the reported event is a reminder that receiving a reset message is not proof of a successful compromise, but it is a meaningful security signal. The safest interpretation of the currently available facts is that X detected or was alerted to attempted activity and is still investigating its scope. Users should rely on the platform’s verified security channels rather than on unsolicited requests for credentials or recovery information, while organizations operating payment-enabled accounts need to monitor the full path from identity recovery to financial authorization.

The investigation will determine the significance

At present, X says it has found no evidence that the attacks succeeded. That statement does not resolve whether attackers reached any protected systems, whether account data was exposed, or whether payment-related functions were targeted; it only describes the company’s position at the time of the report. Further disclosure will be needed to establish whether the incident was limited to repeated reset attempts or formed part of a more extensive campaign.

Until those facts are available, the event is best understood as an unresolved account-security investigation following the launch of a payment service—not as a confirmed breach of X Money. The case nevertheless demonstrates why payment expansion requires security controls that cover social identity, account recovery and financial permissions as one connected risk surface.

Source: link

PAYMENT

About Cobo

Cobo is an institutional digital asset infrastructure provider founded in 2017. The Cobo Agentic Wallet extends Cobo's MPC custody platform to autonomous onchain agents.

Press inquiries: [email protected] · Media kit, executive bios, and additional materials available on request.
Agentic Economy by Cobo

Get this in your inbox every Friday.

The weekly newsletter from the Cobo team — unpacking the most consequential stories in crypto, AI & payments through the lens of institutional custody.