X Investigates Mass Password Reset Spikes Following X Money Rollout
The platform says it has found no evidence of system breaches despite widespread automated attempts to target user accounts.

Social media platform X is investigating a surge in unsolicited password reset requests sent to users following the rollout of its payment product, X Money. According to reporting by TechCrunch, the company stated it has found no evidence indicating that any user accounts have been compromised during the incident.
The influx of automated reset emails prompted complaints across the network on Tuesday. Mridul Singhai, a product engineer at X, addressed the issue in a post on the platform, explaining that malicious actors appear to be targeting account credentials in response to the public availability of the platform's financial services feature.
Singhai noted that bad actors seem to believe the launch of X Money creates an opportunity to gain unauthorized entry into accounts. He added that internal teams are conducting an active investigation into the automated attempts, reiterating that systems show no indication of successful breaches while apologizing for the volume of notifications sent to affected users.
X Money represents the platform's recent expansion into digital financial services, offering users tools such as a linked debit card. The feature is intended to support the network's digital commerce operations by simplifying payment processing for content creators receiving funds directly on the site.
X has not issued a formal statement through its primary corporate accounts or responded to media requests regarding the scope of the incident. However, James Burnham, general counsel at X, warned perpetrators in a public post, writing: “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
Within the platform, account holders have begun circulating advice urging peers to bolster security configurations, specifically by turning on two-factor authentication. X's automated artificial intelligence assistant, Grok, also addressed user inquiries by confirming that attackers were programmatically submitting password reset forms using publicly accessible account handles.
In its automated responses, Grok clarified that the wave of activity did not stem from an internal infrastructure breach or widespread account takeovers, posting that there was “no confirmed system breach or mass takeovers.” The chatbot guided impacted users toward setting adjustments, recommending the activation of Password Reset Protect within the platform's security preferences.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



