This week, X Money opened up to all U.S. Premium and Premium+ subscribers, with the promise of direct money transfers within Elon Musk's platform. By Tuesday, however, the celebration was cut short. Thousands of accounts—including prominent figures in the crypto ecosystem, members of the CoinDesk team, and even some of our own staff—were hit by a flood of unsolicited password reset emails. Some users reported receiving as many as ten within just a few hours.
Key takeaways from this article:
- X Money launched for U.S. Premium subscribers promising direct money transfers, but was quickly disrupted by security incidents.
- Thousands of password reset emails were sent, sparking concern and speculation regarding potential unauthorized access attempts.
Thousands of unsolicited reset emails: X Money in the crosshairs
Mridul Singhai, who works on the product engineering team at X, confirmed the incident on Tuesday. "Attackers seem to believe that now that X Money is widely available, they can gain unauthorized access to accounts," he wrote on X. "We are actively investigating and, as of now, have found no evidence of any compromise." He also apologized for the multitude of emails sent to affected users in error.
So, why such chaos? X Money leverages the banking infrastructure of Cross River Bank, allowing users to send money directly to one another from the platform's dedicated tab, without needing a third-party app. Multiple users shared screenshots showing five, eight, and sometimes ten notifications arriving in rapid succession, before they even had time to grasp what was happening, according to reports compiled by Crypto Briefing. This deluge triggered panic far faster than any official explanation.
Wondering how so many accounts could be targeted at once? The mechanism is almost mundane. X allows anyone to initiate a password reset request simply by knowing a public username, without needing the associated email address. Receiving the email, therefore, does not prove that an attacker has compromised your details—only that they know your handle.
The platform has for some time offered a safeguard called « Password Reset Protect », which adds a mandatory step: confirming the email address or phone number associated with the account before the request proceeds. This feature existed prior to the incident, but few users had taken the time to enable it.
No evidence of a hack at this stage, but caution remains essential
To date, X has found no signs of system compromise. There is no proof that a single attacker is behind every one of these emails rather than a simple bug or an automated reconnaissance campaign testing thousands of usernames in a row. Regardless, the recommendation remains the same for everyone: Enable two-factor authentication, turn on Password Reset Protect, and above all, do not click on any links in these emails, even if they appear to come from X. This five-minute precaution is far better than dealing with an emptied account later. Especially since this type of wave can sometimes serve as a smokescreen: while everyone is focused on reset emails, more patient attackers may be trying less visible methods, such as social engineering or using credentials recycled from other services.
The episode arrives at a difficult time for the credibility of X Money, which has only just emerged from its limited rollout phase. Crypto-linked X accounts are recurring targets for these kinds of tactics, whether it be classic phishing or hijacking to push fraudulent memecoins. Every new financial layer added to Elon Musk's platform further expands the attack surface that bad actors can probe, with or without success.
The news that matters, summarized in 2 minutes. Monday to Friday, in your inbox.