Key takeaways

  • X says attackers are targeting user accounts after the launch of X Money.
  • The warning covers scams that may seek passwords, codes, or payment details.
  • A real X employee should not ask for your password or login code.
  • Users should turn on two-step login and check account activity.

X Money attacks means attempts to take over or misuse X accounts linked to the new payment service. X said attackers are targeting users after X Money launched. The company did not say how many accounts were hit. Users should treat unexpected payment messages as a warning sign.

What are X Money attacks?

X Money attacks are account scams linked to the launch of X’s money service. Attackers may pretend to be X staff, payment agents, or people who need help. Their goal is simple: steal access, money, or personal data.

X Money is designed to let people send, receive, or use money through X. That makes accounts more valuable to criminals. A stolen social media account can also help them trick the victim’s followers.

X warned users about the activity after the service went live, according to TechCrunch. The company gave no public count of successful attacks in the report. That missing number means users should focus on the warning, not wait for a bigger breach.

How do X Money attacks work?

Most account attacks start with a message. It may claim that a payment failed or that the user must confirm an account. The message then sends the victim to a fake login page.

That fake page is called a phishing site. Phishing means a scam that copies a trusted service to steal information. It may look almost the same as an X sign-in screen.

Attackers can ask for a password, a one-time code, or a card number. A one-time code is a short number sent by text or an app. Giving away that code can let a criminal enter the account.

Some criminals may also offer fake refunds or prizes. Others may claim that a user broke a rule. Fear and urgency are useful tools because people act faster under pressure.

Why does the X Money launch raise risk?

Payments create a direct path to money. That changes the reward for criminals compared with ordinary spam. Even a small number of stolen accounts could help attackers reach many more users.

The risk also spreads through trust. A message from a friend’s hacked account may seem real. For example, a follower could send money after seeing a false request from someone they know.

Security experts often call this social engineering. It means using lies and pressure to make people reveal secrets or take an unsafe action. The trick targets human judgment, not just computer code.

X users already face risks from fake support accounts and copied profiles. X Money attacks add a payment story to those older scams. So users should check the sender before clicking or paying.

Typical attack pathFake messageFake loginStolen codeThe final goal may be account takeover, fraud, or theft from contacts.

What should X users do now?

Start with the login settings. Turn on two-step authentication, also called 2FA. It asks for a second proof of identity after the password.

An authentication app is usually safer than text messages. But any second step is better than using only a password. Users should also choose a password that they do not use on other sites.

Never share a login code with someone who contacts you first. X support should not need your password. Users should open the X app directly instead of tapping a payment link in a message.

Check account activity for unfamiliar devices and sessions. Remove access that you do not recognise. If an account looks hacked, change the password, end other sessions, and report the account through X’s official safety and security guidance.

Users should also warn friends if their account was taken over. That quick message can stop others from sending money. People who lose funds should contact their bank or payment provider at once.

What X has said, and what remains unclear

X has confirmed that attackers are targeting accounts after X Money’s launch. However, the company has not publicly shared a full attack count, the main countries affected, or the total amount lost.

Those details matter because they show the size of the problem. Until X releases more data, users cannot tell whether the activity is a small scam wave or a wider campaign.

The company may also need to explain how it checks payment messages and support requests. Clear warnings inside the app could help users spot fake prompts before they act. X’s transparency reports offer wider safety data, but they may not cover this new activity yet.

Warning sign What it may mean Safe response
Urgent payment request Pressure scam Stop and verify another way
Request for a login code Account takeover attempt Do not share the code
Link outside the X app Possible phishing page Open X directly
New device on the account Someone may have signed in End the session and change the password

What X Money attacks mean for users

The warning does not prove that X Money itself was hacked. It says attackers are targeting users around the service. That difference matters because a scam can exploit people without breaking the company’s systems.

For now, the best defence is basic but powerful. Slow down, check the message, protect the account, and never share a secret code. X Money attacks are most likely to work when a user feels rushed.

FAQs

What are X Money attacks?

They are scams or account-takeover attempts that use the X Money launch as a lure.

How can I protect my X account?

Use two-step login, keep your password unique, and never share login codes.

Why should I avoid payment links in messages?

A link can lead to a fake page that steals your password or payment details.

Account security—not a confirmed breach—is the story

Everyone else is reporting an attack wave after X Money’s launch; we are explaining the precise risk. Users reported unsolicited password-reset emails, and X product engineer Mridul Singhai said the company was investigating mass reset attempts. At the time of the disclosure, X said it had found no evidence of successful account breaches. That means the incident should not be described as a confirmed compromise of X Money.

TechCrunch documented the engineer’s statement and user reports. Digital Today independently reported the same password-reset wave, while Cobo’s newsroom summarised the investigation and the lack of confirmed takeovers. X’s official account security guidance is the primary source for defensive steps, including a unique password, two-factor authentication and password-reset protection.

Account attack pathAccount attack path shown in three stages.Reset requestUser alertDefence

Why reset emails can be abused without stealing data

A public username can be enough to trigger a password-reset workflow. If attackers automate that form, users may receive many legitimate emails generated by the platform even though the attackers do not possess the password or inbox. The noise can create panic, train people to click quickly or hide a later phishing message among genuine alerts.

The safest response is to avoid links in unexpected emails and open X directly. Users should confirm that the browser address is x.com before entering credentials. X says it will never ask for a password by email, direct message or reply. That rule is more useful than trying to judge a message only by its visual design.

Account security layersAccount security layers shown in three stages.Password2FAReset lock

How payments change the value of an account

A social account already carries identity, reach and private messages. Adding payments can increase its value to criminals because a takeover may expose payment permissions or make fraudulent requests more believable. It can also let an attacker impersonate the owner to followers who already trust the account.

This does not prove that the payment system itself is vulnerable. It shows why account security must be treated as part of financial-product design. Clear transaction alerts, session controls, recovery safeguards and support escalation become more important when a social identity can initiate or receive money.

Security response sequenceSecurity response sequence shown in three stages.CheckSecureReport

What users should check today

Review active sessions and remove devices you do not recognise. Change reused passwords, secure the linked email account and enable an authenticator app or security key where available. Turn on password-reset protection so a reset request requires additional account information.

If money moved without permission, contact the bank or payment provider immediately and keep copies of messages and transaction records. If only an unsolicited reset email arrived, do not assume the account was entered; verify sessions and security settings first. Our UPI AI-agent rules analysis explains why payment permissions need clear limits, while our ATM security report shows how layered controls reduce financial-system risk.

Source note and verification

This article distinguishes confirmed facts from inference. The confirmed facts are mass unsolicited reset attempts, an active investigation and no evidence of successful breaches at the time of the public statement. TechCrunch, Digital Today and Cobo were cross-checked, while X Help supplies the official defensive guidance.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.