Friday, September 18, 2026
BTC: $78,168 +2.45% ETH: $2,514 +3.39% SOL: $106.50 +6.85% XRP: $1.34 +3.17% ADA: $0.2161 +9.23%

X Hit by Wave of Unsolicited Password Reset Emails, Crypto Figures Among Those Targeted

Unrequested password-reset emails flooded X users on Sept. 1, with crypto figures and journalists among those targeted; X says it found no evidence of a breach.

Unrequested password-reset emails flooded X users on Tuesday. Crypto industry figures and journalists were among those hit. The wave raised account-takeover concerns on a platform that serves as crypto’s primary news wire.

X engineer Mridul Singhai addressed the issue in a tweet on Sept. 1. He apologized and said the company had found “no evidence of any breaches” so far. The activity, he suggested, came from attackers probing X accounts now that X Money is widely available. “We are actively investigating the issue and, so far, have found no evidence of any breaches,” Singhai wrote. “We apologize for the multiple emails and appreciate your patience.”

The reset emails are real. Not spoofed, per Decrypt. They originate from X’s own systems. Users started posting about unrequested resets, login alerts, and account lockouts in early August. Tuesday brought a large surge.

Crypto founder “cap.eth” (@TheCapHimself) posted that someone had been “aggressively” trying to reset his X password. “i have 2fa but i’m still anxious,” he wrote. “anyone else experienced this?” Another user, Molly (@bigmagicdao), asked the same question plainly: “Anyone else experiencing this????”

X has not confirmed a breach. The company’s help documentation says X proactively resets passwords when an account is flagged as compromised or targeted by phishing, sending an email with instructions. Emails come only from @X.com or @e.X.com, per X. The company says it never asks for a password by email.

Several candidate causes exist. None has been confirmed as the trigger.

The reset surge lands against a backdrop of prior X and Twitter data exposures. A January 2022 Twitter API vulnerability let an attacker match email addresses and phone numbers to accounts. The resulting dataset, cataloged on Have I Been Pwned as “Twitter200M,” covers more than 200 million users. Troy Hunt found 211,524,284 unique email addresses in it. Of those, 98 percent had already surfaced in earlier, unrelated breaches.

In April 2025, a hacker using the handle “ThinkingOne” posted a 34-gigabyte file to BreachForums. It held 201 million X user records: screen names, email addresses, account-creation dates, follower counts. Fox News reported the leak. SafetyDetectives checked a sample against live X profiles and confirmed the emails matched active accounts.

Then there is the botnet. Researchers at Breakglass Intelligence found an unsecured command-and-control panel in April 2026. It was actively running stolen credentials against X accounts. In a single 12-minute observation window, the panel tested 722,763 credential pairs and confirmed 18 new compromises. Over its lifetime, the botnet ran more than 4.8 million X accounts through its checker. Two-factor authentication blocked 85.6 percent of attempts. By the time the panel went offline, it had confirmed 138 account compromises out of the 4.8 million attempts.

A separate phishing campaign has targeted X users since July, The Guardian reported. Scammers send emails that replicate X’s real “new device login” alerts. Same logo. Same colors. Correct grammar. Links lead to fake pages built to steal passwords or authorize malicious apps. No breach required.

The reset wave also coincided with a service disruption at Proton, the encrypted email provider some X users rely on for account recovery. Proton Support said it was aware users were having trouble connecting. The provider’s status page pinned the disruption on residual hardware failures from an overheating incident the week before. Unrelated to X, most likely. But it could delay reset emails for affected users.

The pattern has a recent parallel. In January 2026, unrequested reset emails from Instagram coincided with a dataset tied to 17.5 million accounts appearing on a dark-web forum. Forbes reported it. Meta later confirmed a bug had let outside parties trigger the reset emails. It denied any breach of its own systems.

What is not known: whether Tuesday’s surge traces to the 2022 API dataset, the 2025 ThinkingOne dump, the Breakglass botnet, the phishing campaign, or some combination. X has issued no corporate statement confirming a breach. Singhai’s tweet remains the only on-record acknowledgment from the company. The exact scope of which accounts were targeted on Sept. 1 has not been disclosed.

The advice from the data is blunt. Two-factor authentication blocked the large majority of automated takeover attempts the Breakglass panel ran. Users without it had no such margin.