After the launch of payment service X Money, there was a wave of abnormal account activities on the platform. Multiple users reported receiving unsolicited password reset emails. X stated that they are investigating the situation, and so far, no evidence has been found that hackers have successfully gained access to accounts.
Multiple users have received reset emails.
According to Party X, it appears that the attackers believe that since @XMoney has been widely accessible, they can take this opportunity to attempt to gain unauthorized access to users' accounts. The company stated that the current investigation has not found any signs of data leakage or account breaches, but they acknowledge that users may continue to receive related emails as a result.
TechCrunch reports that as of press time, X has not released a more complete explanation through its official company accounts, nor has it responded to further inquiries from the media.
X Money under pressure after going live
X Money is a payment service recently launched by X, which includes features such as bank cards. For X, this service aims to enable creators to receive payments more conveniently within the platform, further promoting the digital payment ecosystem on their platform.
After the payment function was launched, the association between accounts and funds increased, making them more vulnerable to attacks. According to X, this issue seems to be someone using public usernames to trigger password reset forms in bulk, rather than having already breached the platform's system.
- No evidence of system intrusion has been found at this time.
- No confirmation of large-scale account takeovers yet.
- Abnormal operations are related to the password reset process.
Users are reminded to enable two-factor authentication.
As the abnormal situation continues, some users have begun to remind each other on the platform to enable two-factor authentication as soon as possible in order to reduce the risk of account theft. X's chatbot Grok has also replied with steps on how to enable two-factor authentication under some posts, stating that attackers are "triggering password reset requests in bulk."
X's Chief Legal Advisor James Burnham also stated in a post on the platform that X's legal and security teams will investigate and hold accountable those who attempt to harm platform users.











