X Money launch sparks account security concerns as users report password reset emails

icon币界网
Share
AI summary iconSummary
The announcement of X Money’s token launch has raised security concerns as users report receiving unsolicited password reset emails. X stated it is investigating the issue but has found no evidence of account compromises. The company warned that attackers may be exploiting public usernames to send mass password reset requests. Users are advised to enable two-factor authentication to better secure their accounts.
CoinMarketCap reports:

Following the launch of the payment service X Money, unusual account activity occurred on the platform. Multiple users reported receiving unsolicited password reset emails. X stated that it is investigating the matter and has found no evidence that hackers have successfully compromised any accounts.

Multiple users received reset emails.

According to X, the attackers appear to believe that, with @XMoney now widely open, they could attempt to gain unauthorized access to user accounts. The company stated that its current investigation has found no evidence of data breaches or compromised accounts, but acknowledged that users may receive repeated related emails as a result.

TechCrunch reported that, as of press time, X had not yet released a more detailed statement through its official corporate accounts and had not responded to further media inquiries.

X Money came under pressure after launch.

X Money is X’s newly launched payment service, featuring functions such as debit cards. For X, this service aims to make it easier for creators to receive payments within the platform, further advancing its digital payment ecosystem.

After the payment feature was launched, the connection between accounts and funds increased, making them more attractive targets for attackers. According to X, this incident appears to have involved attackers using publicly available usernames to bulk-trigger password reset forms, rather than having breached the platform’s system.

  • No evidence of system compromise has been found.
  • No confirmed large-scale account takeovers at this time.
  • Abnormal activity is related to the password reset process.

User reminder: Enable two-factor authentication

As the anomaly continues, some users on the platform have warned each other to enable two-factor authentication promptly to reduce the risk of account compromise. X’s chatbot, Grok, has replied to certain posts with steps to enable two-factor authentication, stating that attackers are “bulk-triggering” password reset requests.

X's Chief Legal Officer, James Burnham, also posted on the platform that X’s legal and security teams will investigate and hold accountable those attempting to harm platform users.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.