A widespread wave of unsolicited password reset emails has targeted thousands of accounts on X (formerly Twitter), including high-profile crypto personalities, journalists, and everyday users. Many users have reported receiving up to 8 to 10 automated reset emails in rapid succession.
What Is Actually Happening?
-
No Direct Breach Detected: Receiving a password reset email from X does not mean your account, password, or connected email address has been compromised.
-
Abuse of Public Username Recovery: By default, X allows anyone who knows a public
@handleto submit a “Forgot Password” request. The platform automatically dispatches an official reset link to the email address on file. -
Attacker Motives: Automated botnets and bad actors trigger these mass requests for credential stuffing reconnaissance, user harassment, or to cause panic in hopes that targets will fall for follow-up phishing attempts.
Critical Defense: Enable Password Reset Protect
By default, X sends reset links without requiring identity confirmation from the person submitting the request. Enabling Password Reset Protect forces anyone requesting a reset to enter the full email address or phone number tied to the account before an email can be triggered.
PSA Action Checklist
-
Do not click links in unprompted reset emails, even if they appear legitimate.
-
Never share 2FA codes or verification links over direct message or third-party forms.
-
Use a unique password: If your X password is shared across other services, update it immediately via a password manager.
Start the conversation by posting the first comment