X, once known as Twitter, barely got its new money platform through the door before account attackers appeared ready to see what they could get into. The X Money security scare surfaced Tuesday after users reported receiving waves of password reset emails they never requested, creating an uncomfortable opening chapter for a service designed to put payments, cards and other financial tools directly inside X.
The company says it is investigating the activity and, importantly, has not found evidence that attackers successfully breached its systems or took over accounts.
X product engineer Mridul Singhai addressed the reports directly on the platform.
“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts,” he wrote. “We are actively investigating the issue and, so far, have found no evidence of any breaches. We apologize for the multiple emails and appreciate your patience as we work to resolve this.”
That distinction matters. Users receiving unexpected password-reset messages does not automatically mean X itself was hacked. According to information shared publicly by X’s Grok chatbot, attackers appear to be triggering the platform’s password-reset process at scale using usernames that are already public.
Still, the timing could hardly be more awkward.
X Money represents one of the biggest pieces yet of Elon Musk’s years-long attempt to turn X from a social network into what he has described as an all-purpose platform. X took a major step toward that goal in January 2025 when it announced a partnership with Visa for X Money. The planned system included the ability to connect debit cards, fund digital wallets, make peer-to-peer payments, and move money between X and traditional bank accounts.
The product that followed goes even further.
X Money currently promotes direct deposits, bill payments, wires, mailed checks, and instant payments to other X users. It also offers the X Card, which can be used where Visa is accepted, along with eligible cashback benefits and ATM access. X says eligible balances can receive expanded FDIC insurance coverage through a cash sweep program.
However, access is still not completely universal. X Money’s website currently says the service is available to select users in the United States who are at least 18, even as Singhai described the product as “widely available.”
The financial push also connects directly to X’s creator economy.
X’s support documentation says eligible creators can connect an X Money account for payouts. For U.S. creators using X Subscriptions, the company directs them to enroll in X Money to receive their earnings. X is also transitioning away from its older Creator Revenue Sharing program toward its Original Content Rewards program, another system where eligible participants can connect X Money or Stripe for payments.
In other words, an X account increasingly has the potential to represent more than posts, followers and DMs. For some users, it can also become connected to actual income and financial activity.
That changes the value of the target.
X general counsel James Burnham made clear that the company is treating attempts to exploit its users seriously.
“The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”
Meanwhile, users have been warning each other to review their security settings and enable two-factor authentication. Grok has also responded to users discussing the password-reset wave, describing what appears to be happening.
“Yes, a widespread wave of unsolicited X password reset emails is hitting many accounts right now. Attackers are mass-triggering the form using public usernames. No confirmed system breach or mass takeovers.
Enable Password Reset Protect (Settings and privacy > Security and…”
The key phrase there is “No confirmed system breach or mass takeovers.”
So far, X has publicly described an apparent campaign targeting accounts, not a successful compromise of X Money itself. There is also no verified evidence at this point that attackers accessed users’ X Money balances or financial information.
Still, unsolicited password resets are a familiar ingredient in account-targeting campaigns. Even when requesting a reset does not provide access by itself, unexpected security messages can create confusion that scammers may try to exploit through fake support messages, phishing pages, or other attempts to convince users to surrender credentials.
That makes basic account hygiene especially important as X moves deeper into payments. Users should avoid entering passwords through links in unexpected messages, verify that communications actually came from X, and access security settings directly through the platform instead of following suspicious prompts.
For X, the episode highlights the security challenge that comes with transforming a social account into something closer to a financial account. Musk has spent years pushing the idea that X could eventually handle far more of users’ digital lives, with payments serving as a central piece of that vision.
Now that money is entering the equation, attackers appear to be paying attention too.
And X Money may be learning one of the oldest rules in fintech in real time: the second there is money on the table, somebody starts checking the locks.
