X is investigating unsolicited password-reset emails sent to some users, with the timing tied to the rollout of X Money, its financial services offering for eligible US users. So far, the company says there is no evidence of a breach or successful account takeovers.
X Money includes interest-bearing accounts, a Visa debit card, and peer-to-peer payments, with Cross River Bank providing the banking infrastructure. The password-reset emails have raised concerns, but requesting a reset is not the same as actually resetting a password, and recovery still requires access to the associated email or phone number. There is no evidence that anyone accessed X Money accounts or funds, and X has not confirmed that X Money caused the activity. The timing is notable but does not prove a technical connection.
A similar flood of password-reset emails hit Instagram users earlier this year. Such reset flooding can be a nuisance tactic to pressure users into changing passwords, or it can serve as cover for scams. Malwarebytes says the main short term risk for consumers may be phishing that mimics the reset flow, since fake messages can look credible while real reset emails are in circulation.
Mridul Singhai, a product engineer at X, said, "Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts." He also noted "no evidence of any breaches."
For users, the advice is to avoid clicking links or entering codes from unexpected messages, and to open the X app or type x.com yourself when managing account settings. Never share reset codes or two-factor authentication codes, and turn on password-reset protection in X settings, which requires additional account info before a reset can be sent. This setting is located under Settings and privacy, then Account, Security, and Password reset protection.
Enabling two-factor authentication, preferably with an authenticator app or security key, and using a unique, strong password are also recommended. If you have used your X password elsewhere, change it through your X settings. Signs of a takeover include unfamiliar posts, direct messages, profile changes, or login alerts.
Malwarebytes also advises keeping current anti-malware with web protection switched on, saying it can warn users away from fraudulent sites.












