X says attackers are targeting user accounts after the launch of X Money
X is investigating a wave of unsolicited password reset emails targeting users after the X Money payments launch, with no confirmed breaches yet.
Numerous X users reported unsolicited password reset emails following the launch of X Money, the platform's new payments service with accounts held at FDIC-insured Cross River Bank. Product engineer Mridul Singhai said the company found no evidence of successful breaches or mass account takeovers, while the Grok chatbot confirmed attackers are mass-triggering resets using public usernames. Users are being advised to enable two-factor authentication and Password Reset Protect while the investigation continues.
- Mass unsolicited password reset emails hit X users after X Money's launch.
- X says it has found no evidence of successful breaches or account takeovers.
- Grok said attackers are mass-triggering password resets using public usernames.
- X Money accounts are held at FDIC-insured Cross River Bank.
- Users are urged to enable two-factor authentication.
Full article534 words · extracted from techcrunch.com · click to collapse

Attackers are attempting to target X users following the launch of X Money. After numerous X users reported receiving unsolicited password reset emails, a representative said the social media company was actively investigating the issue but had not yet found evidence that the hacks were successful.
On Tuesday, X product engineer Mridul Singhai posted to the social network that the company was looking into users’ complaints about the mass password reset attempts.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” he wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
X Money is X’s newly launched payments service, which includes a bank card with 3% cashback, instant payments, free ATM withdrawals, and other digital banking services. The accounts themselves are held at the FDIC-insured Cross River Bank. For X, the service could make it easier for creators to collect payments on the platform, further facilitating X’s digital economy.
Of course, money changing hands has a tendency to attract bad actors, which is what X says may be happening here.
Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches.
We apologize for the multiple emails and appreciate your patience… https://t.co/zf1pRWbqBX
— Mridul Singhai (@singhai) September 1, 2026
X has not posted details to one of its official company accounts as of the time of writing, and has not yet responded to our press inquiry about the matter.
However, X general counsel James Burnham wrote a threatening post, saying, “The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
As the attacks continue, users are warning each other about the problem and reminding others to enable two-factor authentication , if it’s not already enabled, to protect their accounts. X’s chatbot Grok has also replied to some posts with the steps on how to do so, while also confirming that the attackers are “mass-triggering” the form for password resets using public usernames.
“No confirmed system breach or mass takeovers,” the AI bot said.
Yes, a widespread wave of unsolicited X password reset emails is hitting many accounts right now. Attackers are mass-triggering the form using public usernames. No confirmed system breach or mass takeovers.
Enable Password Reset Protect (Settings and privacy > Security and…
— Grok (@grok) September 1, 2026
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.
Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software.
You can contact or verify outreach from Sarah by emailing [email protected] or via encrypted message at sarahperez.01 on Signal.
View Bio
Text extracted automatically; images, tables and formatting may be missing. Original: https://techcrunch.com/2026/09/01/x-says-attackers-are-targeting-accounts-after-the-launch-of-x-money/