On September 1, 2026, a wave of password reset emails overwhelmed thousands of users on X (including influential crypto accounts). Some even received up to 10 messages in just a few hours. X claims that this is in no way a security breach. However, this attack revives fears of a hacking campaign. Especially since it coincides with the launch of X Money, Elon Musk’s new payment service.

In brief
- Thousands of accounts on X, including several crypto figures, received up to 10 unsolicited reset emails.
- X confirms that it is investigating but has found, at this stage, no evidence of hacking of its systems.
- The company believes attackers have been targeting crypto accounts since the expanded rollout of X Money.
- Experts recommend enabling Password Reset Protect and two-factor authentication without delay.
A phenomenon massive enough to attract the attention of the crypto community
According to initial reports, the origin of this possible attack is found in a massive wave of password reset requests triggered on X. This is the platform purchased and then integrated by xAI.
Investor and analyst Nic Carter was one of the first to alert the crypto community. His call quickly resonated with certain figures in the sector.
Trader cap.eth also reported an aggressive attempt against his profiledespite the activation of 2FA. He clarified:
Someone is aggressively trying to reset my password.
Nathan, another user active in the crypto blockchain, received ten emails in the space of a few hours. Even several employees of CoinDesk confirmed to have been targeted. And yet, two of them had email addresses that were not very exposed. The frequency and magnitude therefore suggest deliberate coordination rather than mere technical chance.
The timing of this attack on X is not trivial
The incident comes as X has officially just deploy X Money for all of its Premium and Premium+ subscribers in the United States. More explicitly, the launch took place on August 31, 2026 (the day before the reset wave). Enough to raise questions!
To allay concerns, Mridul Singhai, a member of X’s Product Engineering team, confirmed the existence of the survey. He declared on X :
The attackers appear to believe that now that X Money is widely available, they can access accounts without authorization. We are actively investigating and, to date, have found no evidence of a violation.
Developed in partnership with Cross River Bank, this service allowssend money directly via the X platform. For crypto users, this development represents a major step towards the integration of digital payments within the social network. That being said, it also turns every account into a potential financial target. Crypto traders who massively use X for their announcements and analyzes therefore constitute a prime prey for malicious actors.
Crypto: X faces a new test of confidence
For the moment, X has not communicated an official figure on the total number of crypto accounts affectednor confirmed the existence of a coordinated hack campaign. The company also did not specify whether the origin of the attempts came from an identified group or from a spontaneous multiplication of automated attempts taking advantage of the notoriety of X Money.
Decryption: nothing indicates today that credential theft actually took place. There is also nothing to completely exclude it as long as the investigation continues.
A worrying precedent nevertheless calls for caution. In 2023, the data from more than 200 million X accounts was already circulating on the dark web following an API flaw in 2021. This breach allowed attackers to link email addresses and phone numbers to user pseudonyms. Available on the dark web since 2023, this information could theoretically be reused.
That’s not all! Digital assets stored on platforms connected to X could also theoretically be exposed if a hacked account served as an access vector. Especially since blockchain offers little recourse in the event of theft due to its transparent nature. The crypto community is therefore demanding more transparency from Elon Musk on the security protocols put in place for X Money.
In any case, this wave of emails illustrates the persistent vulnerability of social platforms as soon as a financial service is linked to them. For crypto users, vigilance remains the best protection. The next full-scale test of X security may well play out around the growing adoption of X Money. Another catalyst to watch: the reaction of crypto regulators to these flaws.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
