Something shifted on X this week, and it wasn’t just another product update. It was the moment a social media account started looking a lot more like a bank account.
X Money—the platform’s long-promised payments service—has rolled out more widely to U.S. Premium and Premium+ users. You can now hold a balance, send money to other handles in near real time, get a metal Visa debit card, and even earn interest on deposits. The money itself sits with partner banks and carries deposit insurance. On paper, it’s a convenient step toward the “everything app” vision. In practice, it has just raised the stakes for anyone who has ever tried to take over an X account.
Attackers noticed immediately.
The sudden flood of password reset emails
On Tuesday, September 1, users across the platform started reporting something strange. Their inboxes filled with password-reset emails they never requested. Some people got several in a matter of minutes. Crypto accounts and higher-profile handles seemed especially hard hit.
X’s own product engineer, Mridul Singhai, addressed it publicly. Attackers, he said, appear to believe that now that X Money is widely available, they can gain unauthorized access to accounts. The company is investigating and has found no evidence of an actual system breach so far. The emails are real—they come from X itself—because attackers are simply hammering the public password-reset form with known usernames.
That detail matters. It means this isn’t a sophisticated zero-day exploit. It’s opportunistic, automated, and driven by a clear motive: the accounts are now worth more.
Why money changes everything
Before X Money, a compromised X account was mainly a reputation problem or a vehicle for spreading spam and crypto scams. Annoying, sometimes damaging, but limited. Now the same login can potentially move actual dollars, request payments, or post from a handle that people trust enough to send money to.
An X account has effectively become a soft banking credential. That single change raises the financial incentive for account takeovers dramatically. Cybercriminals have always followed the money. When social platforms add real financial rails, the targeting intensifies. We’ve seen versions of this before with PayPal, Venmo, and crypto exchanges. X is simply the latest and one of the most visible.
The current wave of reset attempts is just the opening act. Expect the usual follow-on tactics to ramp up quickly:
- Phishing emails and direct messages that look like official X Money notifications (“Activate your higher yield,” “Verify your account to unlock the card,” “Security alert—confirm your details”).
- Fake websites and ads that clone the X Money branding and promise easy returns or early access.
- Impersonation of friends, creators, or brands asking for money via the platform’s own payment features.
- Secondary abuse once an account is controlled—posting scam links, redirecting payments, or using the trusted handle to social-engineer others.
None of these techniques are new. What is new is the payoff. A successful takeover is no longer just about clout or spam. It can mean real funds or a high-trust channel for extracting money from other users.
The human side of the risk
Most people treat their social media logins more casually than their bank passwords. That habit is about to become expensive. Many users still reuse passwords, skip two-factor authentication, or leave recovery options weak. When the same account suddenly holds a balance or can initiate transfers, those shortcuts turn into liabilities.
There’s also a psychological angle. People are used to ignoring the occasional suspicious DM on X. Once money is involved, the same skepticism needs to apply to every unexpected email, every “official-looking” link, and every request that feels slightly off. Scammers are already skilled at manufacturing urgency and authority. Pair that skill with a platform that now moves money, and the social-engineering success rate climbs.
What you can do right now
The practical defenses are straightforward and already available:
- Turn on two-factor authentication, preferably with an authenticator app or passkeys rather than SMS.
- Enable X’s “Password reset protect” setting so resets cannot be triggered by username alone.
- Treat every password-reset email with caution. Do not click the link. Go directly to the X website or app and check your security settings yourself.
- Review connected apps and active sessions periodically.
- If you use X Money, set transaction limits and require extra authentication for larger moves where possible.
X’s legal and security teams have already signaled they will pursue people who try to victimize users. That is welcome, but it does not replace personal hygiene. Platforms can block and investigate after the fact. You still need to make the initial compromise harder.
Looking ahead
X Money is not uniquely dangerous. Any platform that stitches social identity to financial rails creates the same incentive shift. The difference is scale and culture. X has hundreds of millions of users, many of them already comfortable with crypto, online payments, and rapid information sharing. That combination is attractive to both legitimate users and opportunistic attackers.
The password-reset surge this week is an early, noisy signal. The quieter, more damaging campaigns—targeted phishing, convincing impersonations, and gradual account compromises—will likely follow. The platform has made accounts more valuable. Attackers will keep testing every available door.
For ordinary users the lesson is simple. Treat your X login the way you treat your bank login. Because, for a growing number of people, that is exactly what it has become.
