X users have been hit with a wave of unsolicited password reset emails since the launch of X Money, the platform's new payments service. X product engineer Mridul Singhai said attackers appear to believe that now the service is widely available, they can gain unauthorised access to accounts.
He said the company is investigating and has found no evidence of any breach so far, and apologised for the volume of emails.
Interesting insights on X password reset emails
The method is ordinary, and that is the point. According to Grok, X's own chatbot, attackers are mass-triggering the password reset form using public usernames, with no confirmed system breach and no mass account takeovers.
Anyone can look up a username on X, so the reset endpoint can be hit at scale by anyone who wants to. The suggested fix is Password Reset Protect, under Settings and privacy, then Security, which requires additional information before a reset email goes out, alongside two-factor authentication.
What has not happened is an official statement. As of early reporting, X had not posted from any company account or responded to press queries. The public response so far consists of an engineer's post, replies from an AI chatbot, and general counsel James Burnham writing that the legal and security teams will hold accountable any person anywhere on or off Earth who tries to victimise users of the platform.
What others are saying about X password reset emails
TechCrunch reported the wave and noted X had not commented officially or responded to its enquiry. Singhai's post is the closest thing to a company statement, confirming the investigation and the absence of evidence of a breach. Grok's replies described the mass-triggering method and pointed users to Password Reset Protect. No other outlet had reported the incident at the time of writing.
Adding payments changes the threat model
Nothing about X's security changed this week. What changed is that accounts now have a bank card attached, and that alone made them worth attacking. Any business adding payments to an existing product inherits the same problem: the account protection you built for the old product was sized for the old product.
The narrower lesson is the reset endpoint. A public username plus a form that sends an email on demand is a vector, and rate limiting plus a second identifier before sending anything is basic.
It also fits the pattern we have been tracking, from malware reading one-time PINs off Android phones to banks scanning devices. Attackers are going after the recovery path, because that is where the weak link usually sits.
You might also like our piece on the stolen browser cookies circulating in SA, the Lego South Africa data breach and who carries the liability, and why AI financial crime in SA keeps outrunning compliance.
Get more SA tech and business news and subscribe to The Open Letter.


