Thousands of X users reported receiving password reset emails they did not request on Tuesday, with complaints spanning prominent cryptocurrency accounts and at least four CoinDesk staff members. Some users said they received as many as 10 messages within a few hours, prompting concern about a possible account takeover effort or some other coordinated abuse of the platform’s reset process.
The reports do not by themselves show that attackers accessed users’ email addresses or that X suffered a breach. On X, anyone can start a password reset using a public username, which means the platform can send reset messages to the account holder even if the requester does not know the attached email address.
Reports spread across crypto-focused accounts
The wave appeared broad enough to draw attention across crypto circles, where X remains a key venue for project updates, executive statements, trading commentary and fast-moving news. Because so much industry communication flows through the platform, unusual account security activity quickly became a point of concern.
Crypto investor Nic Carter said Tuesday that “a lot of people” were receiving unsolicited reset attempts and urged users to enable X’s Password Reset Protect feature. Another crypto user, cap.eth, said someone had been trying “aggressively” to reset his password despite two-factor authentication already being enabled.
Why the emails do not prove a breach
The existence of reset emails alone does not confirm that attackers obtained account holders’ email addresses. Under X’s security terms, a password reset request can be initiated with a public username, after which X sends the message to the email address linked to that account.
At least four CoinDesk employees said they received similar emails on Tuesday, including two staffers whose X-linked email addresses were not widely used. Even so, that detail does not establish that any underlying email data was exposed, because the reset flow can be triggered without knowing the destination address.
Available protection inside X
X offers a setting called Password Reset Protect that adds an extra verification step. When enabled, the person requesting a reset must also confirm the account’s email address or phone number before the process can continue.
That safeguard is designed to make opportunistic or automated reset attempts harder to carry through. The reports in circulation on Tuesday focused on the volume of unwanted reset messages rather than on confirmed compromises of user accounts.
What is confirmed so far
As of Tuesday, there was no confirmed evidence that X’s systems had been breached or that the platform was experiencing widespread account takeovers. X had not publicly commented on the reset attempts and had not identified any coordinated campaign or security incident.
The clearest confirmed facts are that many users received unsolicited reset emails and that the requests could have been triggered through X’s normal username-based reset mechanism. Whether the activity was part of a larger takeover attempt, routine harassment, or another form of abuse had not been established in the available information.
Source: www.coindesk.com