๐Ÿ“… Saturday, 5 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Badai Email Reset Password Hantam Pengguna X - Insinyur Sebut Targetnya Saldo X Money

Wave of Password Reset Emails Hits X Users - Engineers Point to X Money Balances as the Target

Hundreds of X users suddenly found their inboxes flooded with a barrage of password reset emails. The wave of unsolicited messages sparked concerns over potential account takeover attempts.

The platform’s security team promptly responded to user complaints. Mridul Singhai from X Product Engineering confirmed on Tuesday that internal systems remain intact with no indication of a breach. The wave of requests occurred because X allows anyone to initiate the recovery process simply by entering a public username, prompting the system to send a verification code to the registered contact.

Why Are X Accounts Suddenly Being Targeted?

Singhai suspects financial motives behind the surge in mass reset requests. Attackers are believed to be seeking access to X Money, a feature that significantly increases the value of controlling an account.

The X Money banking service recently expanded to Premium and Premium+ subscribers in the United States. Its features include savings accounts, instant transfers, and a Visa-branded debit card. The main highlight is an annual savings yield offering of up to 6%.

A partnership with Cross River Bank powers the platform’s financial infrastructure. User deposits are protected by FDIC insurance up to $250,000, with coverage extending up to $10 million through a cash sweep program.

The commercial value of accounts is also set to increase with an overhaul of the creator rewards system. X is currently exploring stablecoins like USDC as a creator payout option, scheduled to replace the Revenue Sharing program starting September 8.

Preventing Account Takeovers

While central servers were not breached, end-point security still relies on account owners. Users are strongly advised to enable two-factor authentication. An additional recommended security measure is activating Password Reset Protection, a feature requiring extra information before a reset code is sent.

Each reset code delivered via email is valid for 60 minutes. Once the password change process is completed, the security system automatically logs the account out of all active sessions across all devices.

Users are urged to recognize official communications. Legitimate security emails only originate from @x.com or @e.x.com domains. System messages never contain file attachments and will never ask users to disclose their passwords.

The new reality is clear: as social media platforms transform into bank accounts, attackers’ targets inevitably follow the money.

Source: crypto.news.

Read also: Cronos Back Online via Forced Rollback - But $6 Million Already Escaped to Ethereum


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share