Unsolicited password reset emails hit X users, prompting security alerts
Regulation & Gov ·
A wave of unrequested password reset messages tied to X accounts has triggered warnings from users and security-minded observers, though the cause remains unconfirmed.
Multiple X users have reported receiving password reset emails they did not request, according to Coindesk. The reports describe a surge in these messages arriving without any corresponding action taken by the account holders, raising concern that accounts may be targeted for takeover attempts.
Password reset emails are typically triggered when someone enters a username or email address into a platform's login recovery flow. A spike in unsolicited resets can indicate automated attempts to probe which accounts exist and are active, a common precursor to credential-stuffing or phishing campaigns, though it can also stem from a technical glitch on the platform's own systems. As of the current reporting, it is not established which of these explanations applies to the activity on X.
The episode has drawn attention in part because of X's prominence as a platform where crypto-related accounts, including project teams and executives, are frequent targets for impersonation and takeover schemes used to promote scams. Unsolicited reset emails are often treated as an early warning sign worth flagging even before any account is confirmed compromised, which accounts for the security warnings accompanying the reports.
The cluster of reports has been corroborated across four distinct sources, though the underlying reporting traces to the same account of the phenomenon rather than independent confirmation of a specific cause. No statement from X addressing the reports has been cited in the material reviewed, and no confirmed account compromises have been tied directly to the reset emails.
What remains unresolved is whether the surge reflects a coordinated attempt to test or attack X accounts, an internal system issue generating erroneous reset triggers, or some other explanation entirely. Users affected have been advised to treat the emails as a prompt to review account security rather than to click through any links contained in them, standard guidance for unsolicited reset notifications. Further detail on the scale of the reports, whether X has acknowledged the issue, and whether any accounts have actually been accessed without authorization has not yet surfaced.