Breaking Crypto Whales Accumulate AAVE, UNI, and MOVR Heading Into October
Crypto Market News

X Users Flooded With Unrequested Password Reset Emails Amid Credential-Stuffing Surge

By Mr Whale · September 3, 2026 · 4 min read
Share: X FB TG

Somewhere between checking a chart and refilling coffee, a lot of crypto-adjacent X users opened their inbox this week to something unnerving: not one password reset email, but a stack of them. Five in an hour. Ten by the afternoon. None of it requested. For anyone who has ever had an account taken over, that particular kind of email flood triggers instant dread — and over the past several weeks, it’s been landing in a lot of inboxes at once.

The pattern picked up sharply on September 1, when a fresh wave of unsolicited password reset emails hit X users, several of them prominent figures in the crypto and finance media world. Some also reported login alerts from unfamiliar locations they didn’t recognize, and a smaller number said their accounts were temporarily locked out entirely. None of it is brand new — users have been describing similar symptoms since early August — but the volume and clustering of this week’s surge pushed the issue back into the spotlight.

How the emails are actually being triggered

What’s technically happening is narrower than a classic breach. X’s account-recovery system allows a password reset to be initiated using nothing more than a public username, after which X’s own servers send the reset email to whatever address is attached to that account. Attackers — or automated tools — appear to be feeding large batches of known usernames into that recovery form, generating a flood of real, legitimate reset emails that recipients never asked for. It’s less a hack of X’s infrastructure and more a bulk abuse of a normal recovery feature, though the end effect for a targeted user feels identical to being under attack.

X engineer Mridul Singhai addressed the wave directly, saying the company is actively investigating and has so far found no evidence that any accounts were actually breached. He suggested attackers may believe that with X’s newer @XMoney financial feature now widely available, gaining unauthorized access to accounts has become more lucrative than before — giving a plausible motive for why the targeting has intensified now rather than at some earlier point.

Where the underlying credentials are coming from

Security researchers tracing the activity point to several overlapping sources rather than one clean origin story: a 2021-2022 API vulnerability in Twitter’s old infrastructure, a 2025 leak that exposed roughly 201 million user records, an active credential-stuffing botnet, and a phishing campaign that researchers say has been running since July. One group, Breakglass Intelligence, previously discovered an unsecured command-and-control panel tied to a botnet running stolen credentials against X accounts; in a single 12-minute observation window, the panel tested more than 722,000 username-password combinations and confirmed 18 new account compromises. Over its full operating lifetime, researchers estimate the same botnet ran more than 4.8 million X accounts through its credential checker — though two-factor authentication reportedly blocked upwards of 85% of those attempts.

That last detail is the closest thing to good news in the whole story. The recommended defenses are unglamorous but effective: turning on X’s Password Reset Protect setting, enabling two-factor authentication if it isn’t already on, and simply not clicking links inside unsolicited reset emails, since the safest way to check an account’s status is always to navigate to the platform directly rather than through an email link. For crypto users especially, where an X account often doubles as a public identity tied to real financial activity, this is one of those moments where a few minutes of account hygiene is worth more than any market call.

Account security incidents can affect the safety of linked financial and crypto activity even without a confirmed platform breach. This is not financial or security advice tailored to your specific situation. For broader wallet and account security fundamentals, see coin680’s Bitcoin Academy.


Share: X FB TG
Written by Mr Whale

Mr Whale has been active in the crypto market since 2020 and leads content and research at Coin680. More about our editorial team →

Get the Coin680 Daily Brief

Bitcoin news, market moves, and Academy lessons -- straight to your inbox, no spam.

Leave a Comment