Loading prices…
〽️NEUTRAL

X flooded with unsolicited password reset emails targeting…

No breach has been confirmed, but the volume of reset attempts targeting prominent crypto figures points to a coordinated effort exploiting X's open username-based reset flow.

X flooded with unsolicited password reset emails targeting…
X flooded with unsolicited password reset emails targeting…
X flooded with unsolicited password reset emails targeting…
X flooded with unsolicited password reset emails targeting…

Thousands of X users reported receiving unsolicited password reset emails on Tuesday, with several prominent cryptocurrency accounts and multiple CoinDesk staff members among those affected. Some users received as many as 10 reset emails within a few hours, raising concerns about a coordinated account-takeover campaign or a possible email address leak.

Crucially, the emails do not confirm that attackers have obtained users' private email addresses. X's platform allows anyone to initiate a password reset using only a public username, after which X sends the reset link to the account's associated email. That means the wave could reflect automated username-scraping rather than a database breach. X has not publicly commented on the incident and has not confirmed any coordinated campaign or compromise of its systems.

Why it matters

X carries outsized weight in the crypto industry. Traders, project teams, and executives rely on it as a primary channel for announcements, market commentary, and breaking news. A successful account takeover of a high-profile crypto figure could be used to push scam links, manipulate token sentiment, or spread false information to large audiences before the compromise is detected.

Market impact

Crypto investor Nic Carter publicly urged users to enable X's Password Reset Protect feature, which adds a second step requiring the requester to confirm the account's email address or phone number before a reset proceeds. Cap.eth reported that reset attempts continued even with two-factor authentication active, underscoring that 2FA alone does not block the initial reset request flow. Until X clarifies the source of the spike, enabling Password Reset Protect is the most direct mitigation available.

Frequently asked questions

  1. Does receiving an unsolicited X password reset email mean my account has been hacked?

    Not necessarily. X allows anyone to initiate a reset using only a public username, so the emails can be triggered without the attacker knowing your private email address. No confirmed breach of X's systems has been reported.

  2. What is X's Password Reset Protect feature and how does it help?

    Password Reset Protect adds a second step to the reset flow, requiring the person requesting the reset to confirm the account's associated email address or phone number before X sends the reset link, blocking most automated reset attempts.

  3. Why are crypto accounts being targeted in this wave of reset attempts?

    X is a primary communication channel for crypto traders, project teams, and executives. A successfully hijacked high-profile account could be used to push scam links, spread false market-moving information, or impersonate project teams.

  4. Does having two-factor authentication enabled protect against these reset attempts?

    2FA protects against an attacker completing a login, but it does not block the initial password reset request from being sent. Cap.eth reported that aggressive reset attempts continued despite having 2FA active.

  5. Has X confirmed a data breach or coordinated attack behind the reset email spike?

    No. As of the reporting, X has not publicly commented on the incident, has not identified a coordinated campaign, and has not confirmed any compromise of its systems or user data.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 34m ago
Open original →