Security1 distinct publisher3 min readPublished
Users started getting reset codes they never asked for on September 1. X reports no breach and no takeovers, and its recovery flow still needs the account's email or phone, which leaves phishing as the reachable risk.
The Watch · Security desk

invest
NYDFS zeroes X Money's advertised 6% yield for New York users on October 11 distinct publisher
security
The fluent cohort is the scammed cohort: 70% of 18-to-22s hit by an AI scam1 distinct publisher
build
Search Console measures verified social posts on the same four metrics as owned pages1 distinct publisher
product
PayPal stopped saying no. Payments teams should now plan for a Stripe-owned checkout rail3 distinct publishers
Compiled by The WatchSomething wrong?How this is made
A flood of reset requests buys an attacker cover and confusion, but not access to the account itself. X's recovery flow will not complete unless the requester has access to the email address or phone number on the account [7], so volume alone leaves the credential where it was [15]. What the volume does produce is a stream of genuine X mail arriving in inboxes, which is good cover for a phish built to look like it [10]. Malwarebytes rates that imitation ahead of any defect in X as the immediate consumer risk [14]. The second effect is quieter: repeated alerts push people to rotate passwords that did not need rotating, bury the notifications that do matter, and in some cases lead users to turn protections off to stop the noise [11].
X's account of the motive is a reading of attacker behaviour, an inference rather than a confirmed finding. Product engineer Mridul Singhai wrote that attackers "appear to believe" wider X Money availability gets them into accounts [4]. X has not confirmed that X Money caused the reset traffic, and there is no evidence anyone has reached X Money balances or funds [8]. Earlier this year Instagram users saw a comparable flood of reset mail on a platform with no payments service at all [9], which places the pattern among the things that happen to large consumer platforms whether or not they hold money.
What did change is the payout per successful recovery. Eligible US users now get interest-bearing accounts, a Visa debit card and peer-to-peer payments inside X, with Cross River Bank providing the banking infrastructure [5]. Malwarebytes notes that accounts with payment access, large followings, business use or social-engineering value are the attractive ones [13]. That is the part of the editor's repricing thesis the evidence carries: the email inbox and the phone number behind an X account now sit on the path to a card, and the activity on the wire looks like bulk requests against exactly that path [6].
The control that changes the arithmetic is free and already shipped. X's password-reset protection requires additional account information, such as the email address or phone number, before X will send a reset link or code at all [12]. It sits four levels down in the menu, under Settings and privacy, then Account, then Security [16]. Layer an authenticator app or a security key on top, and never hand a reset code to anyone who contacts you [17].
Until X reports a completed reset, the honest description of this is a noisy and so far unsuccessful probe of the recovery path against a platform that has just raised the value of the accounts behind it [2][5].
Ranked by verification strength, evidence, and original report placement.
X says attackers may be targeting accounts because its X Money payments service is now more widely available.
In a public post, X product engineer Mridul Singhai said: "Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts." He said X was actively investigating, apologized for the repeated emails, and said the company had found "no evidence of any breaches."
X's recovery process requires access to the email address or phone number associated with the account before someone can complete a reset.
X is investigating a wave of unsolicited password-reset emails and says it has found no evidence of a breach or of successful account takeovers so far.
X users began reporting unexpected password-reset emails and codes on September 1.
X Money gives eligible US users financial services inside X, including interest-bearing accounts, a Visa debit card and peer-to-peer payments; Cross River Bank provides the banking infrastructure behind the service.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One public post, one retelling
Strip out the advice and what remains rests on a single X engineer's post: the September 1 start, "no evidence of any breaches," and the description of how X's recovery flow gates a reset. Malwarebytes relays all three faithfully and adds useful discipline of its own — the Instagram comparison, the reminder that a reset request is not a reset — but nobody outside X has verified the timeline, tested the recovery gate, or seen the traffic. The phishing and target-value arguments are reasoning, clearly labelled as such, not observation.
Product live, incident unmeasured
Two different things are being adopted here and only one is documented. X Money is plainly shipped — US availability, interest-bearing accounts, a debit card, a chartered bank behind it — though without a single user or volume figure. The reset wave, the actual subject, has no measured extent at all: how many inboxes, over how many hours, against which accounts. "Users began reporting" is the whole quantification.
Headline links what the text unlinks
The framing ties a payments launch to an attack wave; four paragraphs later the same text concedes no breach, no takeover, no access to funds, no confirmed causation, and a precedent on a platform with no payments at all. Malwarebytes is the one supplying those caveats, which keeps the overstatement modest — the stretch belongs mostly to X, whose motive theory is the only causal explanation anyone has offered and happens to place the blame outside its own systems.
Both narrators have a stake
X's account converts an abusable reset endpoint into a compliment to its new product: attackers came because the money arrived. Malwarebytes, for its part, closes the guidance with Scam Guard and Identity Theft Protection promotions and a line about scammers only needing one click. Neither interest makes the reporting wrong, and the caveats here cut against the vendor's own drama, but the story's only two voices are the company under scrutiny and a company selling the remedy.
Sound reading, single channel
We can be reasonably sure what X said and what Malwarebytes recommends; that much is verbatim. We are far less sure the reset mail has anything to do with X Money, and we have no basis at all for judging how widespread the wave was or whether any account was ultimately lost. A second outlet, or one number from X, would move this a long way.