X Money Launch Triggers Password Reset Email Scam Wave on X

TL;DR
- X is investigating a wave of unsolicited password reset emails reported by users in the days following the rollout of its new X Money payments feature.
- Attackers appear to be exploiting confusion around the launch with phishing tactics, using fake reset emails to steal login credentials and potentially access linked financial information.
- Users are urged to avoid clicking links in unexpected emails, enable two-factor authentication, and only reset passwords directly through the official X app or website.
A Flood of Unexpected Emails
In the days since X rolled out its long-anticipated X Money payments service, many users have reported receiving password reset emails they never requested. The surge was quickly flagged across the platform itself, where users posted screenshots of identical emails arriving in rapid succession, often within hours of the X Money announcement.
X has acknowledged the reports and said it is actively investigating the cause. While the company has not confirmed a data breach or a direct vulnerability in X Money, it stated that it is looking into whether automated systems are being abused to trigger legitimate password reset requests or whether attackers are sending spoofed phishing emails designed to look like them.
Anatomy of the Scam
Security researchers tracking the activity describe two overlapping tactics that make this wave particularly deceptive.
The first involves abuse of X's legitimate password reset system. Attackers with access to a list of emails or usernames — often compiled from previous third-party breaches — can enter those addresses into the real "Forgot password?" flow on X. This causes X's own servers to send a genuine reset email, which can overwhelm and confuse recipients.
The second, more dangerous tactic is pure phishing. In this version, attackers send fake emails that mimic X's official password reset design, complete with similar logos, formatting, and urgent language. These emails contain a button or link that directs users to a cloned login page. Any credentials entered there are immediately captured by the attackers, giving them full access to the account.
In both cases, the timing is key. Because users are expecting communications about X Money, account verification, and new terms of service, they are more likely to view a password-related email as legitimate and act quickly without verifying the sender.
Why the X Money Launch Created a Perfect Opening
The rollout of X Money marks X's biggest push into financial services to date, allowing users to send peer-to-peer payments, store funds, and link bank accounts for future commerce features. Any product that connects a social account to money becomes an instant high-value target for cybercriminals.
Analysts note that major platform changes create a window of opportunity for scams for three reasons. First, users anticipate legitimate emails from the platform and are less skeptical. Second, attackers can craft highly convincing lures referencing "X Money activation," "verify your wallet," or "secure your payments account." Third, a compromised X account is now potentially more lucrative than before if it is linked to payment credentials or identity verification data.
Even if X Money's infrastructure itself has not been compromised, the perception that accounts are now tied to financial assets makes users more anxious — and more likely to click a link that promises to "protect" their account.
The Real Risks for Users
A hijacked X account has always been a serious issue, but the stakes are now higher. Beyond reputational damage, spam, and scams spread to followers, attackers who gain access could attempt to pivot to financial fraud.
Potential risks include harvesting personal information stored in the account, attempting to access linked X Money balances or connected bank details, using the verified identity of the account to scam contacts, and leveraging direct messages to spread further phishing links. For creators, businesses, and users with large followings, the loss of an account could also mean loss of revenue and audience access.
How to Protect Your Account Right Now
X and independent security experts are recommending several immediate steps for all users, whether or not they have received a suspicious email.
Do Not Click Email Links to Reset Your Password
If you receive an unexpected password reset email, do not click the button inside it. Instead, open the X app directly or manually type x.com into your browser and navigate to Settings to change your password from there. Check the sender address carefully — legitimate emails from X come from its official domain.
Enable Strong Two-Factor Authentication
Turn on two-factor authentication using an authenticator app or a hardware security key rather than SMS if possible. This ensures that even if your password is stolen, attackers cannot log in without the second factor.
Check Your Account Activity and Revoke Access
Review your account's login history, active sessions, and connected apps. Log out of all other sessions and revoke access for any third-party applications you do not recognize.
Secure Your Email Account
Since password resets flow through your email, make sure your email account itself is secured with a strong, unique password and two-factor authentication.
X says it is monitoring for automated abuse of its reset system and working to block malicious domains impersonating its login page. The company advises users to report suspicious emails through its official Help Center and to forward phishing attempts for further investigation. Until the investigation concludes, experts say treating any unsolicited password reset email as suspicious is the safest approach.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!