X users flooded with automated password reset emails

Attackers automated X’s recovery form to trigger real password-reset emails to many users; X says investigators found no breach and apologized for the volume.

On Tuesday many X users received unsolicited password reset emails sent from X itself, with some inboxes recording multiple messages within minutes. One user reported eight resets in three minutes. X apologized for the volume and said investigators have found no evidence of a breach.

The activity involved repeated submissions of public usernames to X’s account-recovery form. The form accepts a username alone, and automated submissions generated genuine reset messages to the addresses or phone numbers tied to those accounts. Security observers noted attackers often use large, recycled lists of usernames and email addresses from criminal markets.

Mridul Singhai, a product engineer at X, described the incident as a “major hack attempt,” wrote that investigators have found no signs of a breach so far, and apologized for the multiple emails. X’s official accounts, including X Support and X Money, did not add further public comment.

The campaign coincides with broader changes to X’s products. X Money began peer-to-peer payments for U.S. Premium subscribers in late June, with deposits held at Cross River Bank and federal insurance referenced in company materials. That payment feature links certain account logins to financial services.

Security specialists said a compromised account could be used to promote fraudulent tokens or to attempt to access linked wallets. They also warned that fake two-factor authentication prompts have been used previously to trick users into revealing credentials and drain cryptocurrency wallets.

X’s help pages include a Password reset protection setting that requires the recovery form to provide the email address or phone number on file before sending reset instructions. Former X product lead Nikita Bier posted a screenshot of the toggle and urged users to enable it. Security practitioners also recommend using an authenticator app instead of SMS for two-factor authentication and adding a passkey tied to a personal device.

The incident echoes a July 2020 breach in which attackers manipulated staff to reach an internal admin tool, forced password resets on about 130 accounts and stole roughly $118,000 in Bitcoin. The current activity appears to be conducted externally through the public recovery form rather than by using employee credentials.

It is not yet clear whether X will add technical limits on how often a single account can trigger recovery emails or otherwise rate-limit the recovery form. Company statements to date have focused on the ongoing investigation and the absence of evidence for an internal breach. Users are being urged to enable available account protections and stronger authentication to reduce the risk of account takeover.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author