Social media platform X is experiencing a widespread rise in unauthorized access attempts, sparking growing security concerns among its user base.
The spike in malicious activity coincided directly with the recent rollout of X Money, the platform’s integrated digital payment service.
Attackers are targeting user accounts by triggering automated, high-volume password reset requests en masse.
Thousands of profile owners report receiving unexpected verification emails, signaling that bad actors are attempting to break into accounts tied to the new financial ecosystem.
Platform engineers believe cybercriminals are operating under the assumption that the expansion of X Money makes compromised accounts far more valuable.
By gaining control of individual profiles, attackers likely hope to exploit stored payment methods or drain digital wallet balances linked to the new feature.
Addressing the widespread reports, X product engineer Mridul Singhai confirmed that an internal investigation is currently underway.
Singhai emphasized that the automated reset wave stems from outside actors attempting to exploit the public rollout of X Money to compromise users.
Despite the overwhelming volume of unauthorized requests, X confirmed that its system infrastructure remains fully intact.
Preliminary technical audits show zero evidence of successful breaches or unauthorized account takeovers resulting from the ongoing campaign.
The engineering team formally apologized to affected users for the influx of system notifications caused by the reset attempts.
Work is actively continuing behind the scenes to rate-limit malicious reset requests and safeguard the user community during the rollout.
