Illustration for: Attackers Hit X Accounts Right After X Money Went Live

Attackers Hit X Accounts Right After X Money Went Live

X said attackers began mass-triggering password reset forms using public usernames immediately after X Money became widely available, with the company reporting no evidence of successful account takeovers.

TC
By the Markets Desk
Edited by Trace Cohen ยท Early-stage VC & angel ยท Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

The attack pattern is enumeration rather than compromise -- mass password reset requests against public usernames, betting that a payments balance makes takeover more valuable

2

X product engineer Mridul Singhai said attackers 'appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts'

3

X reports no confirmed breaches and no successful takeovers, and general counsel James Burnham threatened legal action against the attackers

4

The company is pointing users to two-factor authentication and Password Reset Protect, an opt-in setting most consumers have never enabled

TC

The VC Read ยท Trace's Take

Trace Cohen

Public permanent handles plus a stored balance is the worst combination in consumer fintech, and X shipped it in that order. No confirmed takeovers yet, which is the honest headline. But the fix -- mandatory step-up auth at the moment money enters the account -- is a product decision, and retrofitting it across a few hundred million accounts is far more expensive than building it first. If you are underwriting a consumer fintech, ask when step-up authentication becomes mandatory in the user journey. "Optional in settings" is not an answer.

Analysis

X said on Sept. 1 that attackers were mass-triggering password reset forms against accounts using publicly visible usernames, a wave that began as X Money reached wide availability, TechCrunch reported. X product engineer Mridul Singhai said attackers "appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts." The company found no evidence of any breaches and no confirmed takeovers. General counsel James Burnham threatened legal action.

The mechanics matter for anyone shipping payments on top of a social graph. X Money adds a bank card and payment collection for creators to a platform where the primary identifier -- the handle -- is public by design and permanent. That makes credential-stuffing and reset-flow abuse cheap: the attacker does not need to discover targets, only to enumerate them. Every social platform that has added money on top of public identity has faced the same first week. Cash App, Venmo and Telegram wallets all did. Pulse has previously covered X as it has pushed further into ad and now payments products.

X's recommended mitigations are two-factor authentication and Password Reset Protect, a setting buried in Settings and privacy under Security. Both are opt-in. That is the structural problem: the account population most attractive to attackers -- high-follower creators now holding a balance -- overlaps only partially with the population that has enabled hardware-backed 2FA. Platforms that have solved this, notably Coinbase and Stripe-hosted checkouts, made step-up authentication mandatory at the moment money is added rather than optional at signup.

โ€œX is running this launch with a security team that has been repeatedly reduced since 2022, which is the resource constraint underneath the incident.โ€

The absence of confirmed compromise is genuine and worth stating plainly. This is a story about attempted attacks and about attacker intent, not about a breach. What it demonstrates is that the threat model changed the day the product shipped, and that the defenses on offer are the same ones X had before there was money in the account.

The regulatory dimension is not trivial either. A payments product with a stored balance pulls X into money transmitter licensing state by state, and state regulators examine account takeover controls as part of that supervision. A publicized wave of reset abuse in the launch window creates an examination record before the product has scale. Cash App's parent Block spent years and a consent order working through similar scrutiny; PayPal and Venmo built dedicated account-integrity organizations for the same reason. X is running this launch with a security team that has been repeatedly reduced since 2022, which is the resource constraint underneath the incident.

For fintech founders the transferable lesson is sequencing: mandatory step-up authentication should ship before the balance does, not as an advisory afterward. Retrofitting it onto an existing account base is a support burden every consumer fintech underestimates, and X now has to do it live.

ShareXLinkedInEmail

More on

X โ†’

Key Sources

3 sources

Reported by TechCrunch ยท First reported by TechCrunch ยท Analysis by Value Add Pulse.

โ† Back to Pulse

THE WIRE in your inboxโ€” Tech, startup & VC news with Trace's take. Free, no spam.