Investigation: A Coordinated Attack on X's New Financial Platform
Following the launch of X Money, I have been monitoring reports of a significant surge in account compromise attempts targeting X users. This pattern of activity appears to be more than coincidental — it reflects a calculated strategy by malicious actors seeking unauthorized access to user accounts in anticipation of financial transactions on the platform.
On Tuesday, product engineer Mridul Singhai acknowledged these developments on X, stating that attackers believe they can exploit the newly launched payments service to gain unauthorized access to accounts. As of our reporting, the company has not found evidence of any successful breaches.
"Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts," Singhai wrote. "We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this."
What is particularly concerning is that these attacks appear to be mass-triggered using public usernames, indicating a scalable approach to compromise accounts rather than targeting individuals specifically.
The Mechanics of the Attack
Our analysis indicates that attackers are leveraging the password reset functionality to inundate users with unsolicited emails. This is not an isolated incident but part of a broader strategy to identify and exploit vulnerabilities in user account security protocols.
X's chatbot, Grok, confirmed this pattern:
"Yes, a widespread wave of unsolicited X password reset emails is hitting many accounts right now. Attackers are mass-triggering the form using public usernames. No confirmed system breach or mass takeovers."
This method allows attackers to probe accounts without necessarily compromising them directly, potentially leading to credential stuffing or phishing attempts if users inadvertently click on malicious links in these emails.
X Money: A New Target for Cybercriminals
X Money represents a significant development in the platform's evolution — integrating banking services with social interaction. The launch of this service has made X a more attractive target for cybercriminals, who are now actively seeking to exploit its financial capabilities.
The service includes features such as a bank card with 3% cashback, instant payments, and free ATM withdrawals. These financial benefits come with increased risk, particularly for users who may not have previously engaged in payment transactions on the platform.
It is important to note that X has partnered with FDIC-insured Cross River Bank, which adds a layer of regulatory protection for user accounts. However, this does not eliminate the potential for targeted attacks on individual user credentials or social engineering attempts designed to gain access to these accounts.
Platform Security Measures and User Preparedness
While X has not yet responded to our inquiries regarding the current situation, its general counsel James Burnham posted a public statement asserting that the company's legal and security teams would pursue criminal charges against anyone attempting to victimize platform users.
"The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users," Burnham wrote.
This statement underscores the seriousness of the situation. However, it also emphasizes that user preparedness remains a critical component of overall security. I recommend that all X users enable two-factor authentication (2FA) immediately if they haven't already done so.
The platform's chatbot Grok has provided clear instructions on how to activate 2FA:
- Navigate to Settings and Privacy
- Select Security and Privacy
- Enable Password Reset Protect
A Broader Trend in Digital Banking Security
The recent surge in account compromise attempts on X aligns with broader trends in digital finance security. As more social media platforms integrate payment features, we are witnessing a corresponding increase in attacks targeting these new financial entry points.
This trend is not unique to X — it reflects a general pattern where platforms that introduce financial services become attractive targets for cybercriminals. The combination of public user data and transactional capabilities provides malicious actors with valuable information and potential access points.
Our review of similar incidents shows that early responses to such threats often include immediate security protocol updates, public awareness campaigns, and coordination with cybersecurity experts to identify and neutralize attack vectors.
Implications for Future Platform Development
This incident serves as a crucial reminder for platform developers integrating financial services. Security must be considered from the outset of any new feature launch, not as an afterthought.
X's experience highlights the need for robust account verification systems and proactive threat monitoring. It also emphasizes how quickly security measures can be tested when new features are introduced to a large user base.
For platforms like X, which are building their digital economies around creator monetization and user interaction, it's essential that these systems are resilient to exploitation. The balance between user accessibility and account security is delicate, but with proper planning, both can be achieved.
Conclusion: Vigilance is Key
The attacks on X users following the launch of X Money represent a typical example of how new financial features on social platforms become attractive targets for cybercriminals. While X has not yet confirmed breaches, the volume and nature of these attack attempts suggest a significant concern that requires immediate user attention.
As someone who regularly reviews platform security trends and user experience developments, I strongly encourage all X users to verify their account security settings and remain vigilant against phishing or social engineering attempts. These attacks may be ongoing, but they are not necessarily indicative of a system-wide compromise — yet.
We will continue to monitor the situation as it unfolds and provide updates on any new developments from X's side. In the meantime, staying informed about security best practices and remaining cautious with account access information remains our top priority.
Key Facts
- Primary Entity: X
- Service Launch: X Money
- Attack Type: Mass password reset email attempts
- Attack Method: Public usernames used to trigger password reset forms
- Bank Partnership: FDIC-insured Cross River Bank
- Security Measure: Password Reset Protect
- Company Response: Investigating issue, no breaches confirmed
- Platform Engineer: Mridul Singhai
Background
X launched X Money, a new payments service that includes features such as a bank card with 3% cashback, instant payments, and free ATM withdrawals. The service is held at FDIC-insured Cross River Bank. Following the launch, attackers began targeting user accounts with mass password reset emails, exploiting the platform's new financial capabilities. This pattern of attacks appears to be coordinated rather than random.
Quick Answers
- What happened to X after launching X Money?
- X faced a surge in account compromise attempts following the launch of X Money as attackers targeted user accounts with mass password reset emails.
- When did X Money launch?
- X Money launched before reports of the coordinated attack were published on September 1, 2026.
- Who is Mridul Singhai?
- Mridul Singhai is a product engineer at X who confirmed that attackers believe they can gain unauthorized access to accounts now that X Money is widely available.
- What is X Money?
- X Money is a newly launched payments service by X that includes features such as a bank card with 3% cashback, instant payments, and free ATM withdrawals.
- Why are attackers targeting X users?
- Attackers believe they can exploit the newly launched payments service to gain unauthorized access to accounts after X Money became widely available.
- How are attackers conducting these attacks?
- Attackers are mass-triggering password reset forms using public usernames to inundate users with unsolicited emails.
- Is there any evidence of successful breaches?
- X has found no evidence of any successful breaches despite the coordinated attack attempts on user accounts.
- What security measures does X recommend?
- X recommends that users enable two-factor authentication (2FA) and Password Reset Protect to secure their accounts against these attacks.
Frequently Asked Questions
What is the current status of X Money security?
X has not found evidence of any successful breaches but is actively investigating the issue and working to resolve it.
How can users protect their accounts from these attacks?
Users should enable two-factor authentication (2FA) and Password Reset Protect on their accounts as recommended by X's chatbot Grok.
What is the relationship between X and Cross River Bank?
X has partnered with FDIC-insured Cross River Bank for its financial services, which adds a layer of regulatory protection for user accounts.
What is the purpose of the password reset emails?
The purpose is to probe account security by mass-triggering password reset forms using public usernames without necessarily compromising the accounts directly.
Source reference: https://techcrunch.com/2026/09/01/x-says-attackers-are-targeting-accounts-after-the-launch-of-x-money/



Comments
Sign in to leave a comment
Sign InLoading comments...