X’s new payments app X Money hit by mass hacking attempt

4 days ago  ·  5 min read
By Sarah Miller - usagevpn.com
1200x675_cmsv2_6d3015ed-73bd-5d93-958f-fc2e28d123a9-9898527

X Money Faces Coordinated Account-Targeting Campaign Days After Full Subscriber Rollout

Usagevpn.com – The payments arm of Elon Musk’s social media platform found itself at the center of a large-scale account-targeting operation within weeks of opening its doors to every paying subscriber. Beginning shortly after X Money completed its expansion beyond the initial invite-only cohort, a wave of unsolicited password-reset notifications flooded inboxes of users across the platform. The company confirmed it was investigating the phenomenon but stated that, as of the latest update, no confirmed breaches had been identified.

How the Attack Appears to Work

Analysts and the company’s own preliminary findings suggest the mechanism is straightforward yet effective: attackers are believed to be programmatically submitting the public-facing password-reset form en masse, using usernames that are openly visible on X profiles. Because every account on the platform carries a public handle, the pool of targets is effectively unlimited. Each submission triggers an automated confirmation email to the associated address, creating the appearance of a routine account-recovery event.

For a conventional social media account, such an email might be an annoyance at worst. For a wallet that holds balances, processes transfers, and executes peer-to-peer payments, the stakes shift dramatically. If an attacker were to complete the reset flow and gain session access, they would not merely read posts or change a display name — they would control a financial instrument embedded in the platform.

X Money: Scope and Timeline

X Money debuted in July under a restricted, invite-only framework, allowing a small group of early adopters to test the feature set. On 31 August, the service was opened to all Premium and Premium+ subscribers, dramatically widening the user base overnight. The platform’s financial toolkit includes holding balances, initiating and receiving payments, and executing peer-to-peer transfers — all executed within the X interface without requiring users to leave the app.

This rapid scaling, from a closed pilot to a full subscriber rollout in roughly six weeks, compressed the window during which security teams could harden infrastructure and monitor for anomalies. The timing of the password-reset surge, landing squarely in that post-expansion period, has drawn attention to whether the platform’s fraud-detection systems were calibrated for the new volume of accounts.

Company Response and Legal Posture

James Burnham, X’s general counsel, issued a pointed statement addressing the incident publicly on the platform itself:

“The legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform’s users.”

The language signals an intent to pursue civil and criminal remedies against identified actors, though no specific individuals or entities have been named publicly. The statement also underscores that the company views the episode not as a minor nuisance but as a direct challenge to user trust in its financial product.

User Backlash and the Role of Grok

The notification wave quickly became a trending topic on X itself. Users posted screenshots of the unexpected emails, urged one another to verify that two-factor authentication was active, and shared tips for recognizing legitimate versus fraudulent correspondence. The platform’s own AI assistant, Grok, entered the conversation by replying to individual posts with step-by-step guidance on enabling multi-factor authentication and reviewing active sessions.

While receiving a single password-reset email does not, by itself, confirm a compromise — particularly for accounts protected by multi-factor authentication — the sheer volume of simultaneous notifications raised alarm. Many users interpreted the pattern as evidence of a coordinated sweep rather than isolated user error.

The Second Wave: Follow-Up Phishing Emails

Complicating the picture, a subset of affected users reported receiving a second email shortly after the initial reset confirmation. These follow-up messages were styled to resemble official X correspondence and urged recipients to “change their password” via a hyperlink. The embedded link, however, pointed to a look-alike domain rather than the genuine X sign-in page, a classic credential-harvesting technique.

The two-stage sequence — first a mass-generated reset notification to create urgency, then a targeted phishing email to capture login details — suggests a more elaborate multi-step operation than a simple form-spam exercise. If successful, an attacker would obtain both the username (already public) and the password (entered on the fake page), potentially bypassing even accounts that had not yet enabled multi-factor authentication.

Regulatory Shadow: Banking Partners and Deposit Yields

The security episode lands against an already sensitive backdrop. X Money’s operational architecture depends on partner banks, most notably Cross River Bank, which holds the customer deposits behind the wallet balances. Cross River Bank has previously been subject to regulatory enforcement actions, a fact that has drawn scrutiny from commentators and consumer-protection advocates questioning whether the platform’s banking relationships meet the standards expected of institutions safeguarding retail funds.

Separately, X Money has promoted a 6% annual yield on deposited balances as a headline feature. That rate sits well above prevailing federal benchmark rates for comparable short-term instruments, prompting questions about the sustainability of the offer and the risk profile of the underlying lending or investment activities that generate the spread. In a period when users are already anxious about account security, any additional uncertainty about where their money actually sits and how it is managed amplifies the reputational stakes of the current incident.

What Users Can Do Now

Platform guidance and community consensus converge on a short checklist: confirm that two-factor or multi-factor authentication is enabled in account settings; review the list of active sessions and revoke any that are unrecognized; treat any email asking for a password change with skepticism until verified through the in-app settings page rather than a hyperlink; and, where possible, avoid entering credentials on pages reached through email links. For X Money specifically, users may wish to check their balance and recent transaction history directly within the app to confirm no unauthorized transfers have occurred.

As the investigation continues, the episode serves as an early stress test for X Money’s transition from a niche pilot to a mainstream financial product. The speed with which the company identifies the source of the reset storm, communicates findings to affected users, and demonstrates that no funds were moved will shape whether subscriber confidence in the wallet survives its first major security scare.

Frequently Asked Questions

What is X s new payments app X Money?

X s new payments app X Money is the main topic of this guide. The article explains the context, practical details, and next steps readers should understand.

Why does X s new payments app X Money matter?

X s new payments app X Money matters because readers are looking for a useful answer, not just a short summary. Good content should match search intent and help them decide what to do next.

More from this category