HomeBlockchainRegulationX password reset issue surges as botnet tests 4.8 million accounts

X password reset issue surges as botnet tests 4.8 million accounts

Something odd has been happening in a lot of people’s inboxes lately. Since early August 2026, X users have reported receiving password reset emails, login alerts, and even temporary account lockouts they never triggered themselves. The messages are genuine, sent from X’s own systems, which is exactly what makes the X password reset issue so unsettling — nothing about them looks fake, yet nobody asked for them.

Key takeaways

  • X users have been reporting unsolicited password reset emails, login alerts, and lockouts since early August 2026, with a fresh surge on September 1.
  • X engineer Mridul Singhai says the company has found no evidence of any breach so far and is actively investigating.
  • Researchers link the activity to a 2021-2022 Twitter API flaw and a 2025 leak of 201 million user records, plus an active botnet and a phishing campaign running since July 2026.
  • A botnet tested more than 4.8 million X account credentials over its lifetime, with two-factor authentication blocking 85.6% of the attempts.
  • Proton’s email service is separately dealing with a hardware-related outage that could delay reset emails for some users, though no link to the X incidents has been confirmed.

Unsolicited password reset emails hit X users since August 2026

The pattern started roughly a month ago and has only intensified. X account holders describe getting password reset messages out of nowhere, followed by login alerts flagging sign-ins from unfamiliar locations. Some say accounts they hadn’t touched in weeks were briefly locked.

What makes this different from a typical phishing scare is that the emails are legitimate. They come directly from X’s own mail servers, not spoofed addresses. That confirms someone — or something — is actively requesting resets on other people’s accounts, even if the account owner never clicked anything.

The timing lines up with a broader rollout: X Money, the platform’s payments feature, expanded to eligible U.S. subscribers around the same period. That expansion appears connected to why attackers are suddenly interested in gaining control of X accounts in the first place.

X investigates but stops short of confirming a breach

X says its internal review has turned up no proof that its systems were compromised, even as the company continues digging into the reports. X Product Engineering team member Mridul Singhai addressed the wave of complaints directly on the platform, apologizing for the disruption.

“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches,” Singhai wrote, adding an apology “for the multiple emails” and thanking users for their patience.

Crypto.news notes an important technical nuance: an unsolicited reset email alone doesn’t prove a password was exposed or that an account was accessed. X’s recovery flow lets anyone start the process just by entering a username, email, or phone number tied to an account, after which a confirmation code goes to the registered contact method. That means the reset wave could reflect repeated attempts to trigger codes rather than confirmed break-ins — though it’s still a sign someone is targeting the account.

X’s guidance for password recovery states that reset codes sent by email stay valid for 60 minutes, and completing a reset logs the account out of every active session. Changing a password from an existing logged-in session, by contrast, leaves that session active.

Old API flaw and leaked datasets keep resurfacing

Even without a fresh hack, X has plenty of old exposed data still circulating that could be fueling the current X data breach investigation. A vulnerability in Twitter’s API from 2021 into January 2022 let an attacker match email addresses and phone numbers to specific accounts. The resulting dataset, covering more than 200 million users, is now catalogued on Have I Been Pwned. Site founder Troy Hunt examined it and found 98% of the addresses had already surfaced in earlier, unrelated breaches — meaning most of this data has been floating around for years.

A newer leak This exacerbates the issue further. During April 2025, an individual operating under the alias ThinkingOne released a 34-gigabyte dataset comprising 201 million X user accounts, including usernames, email addresses, and the dates when those accounts were established, and follower counts — on the forum BreachForums, according to Fox News. Researchers at SafetyDetectives sampled the file and confirmed the emails matched active X profiles.

This isn’t the platform’s first rodeo with exposed credentials. Twitter and X have dealt with versions of this problem before, going back to a 2016 sale of 33 million logins, through a 2023 bug that let anyone hijack an account with a single click — a flaw whose discoverer reportedly got banned rather than rewarded, according to Decrypt’s reporting on past incidents.

Botnet credential stuffing and phishing campaigns compound the risk

Neither leaked dataset needs a brand-new hack to keep doing damage — old email addresses are being recycled into active attacks right now. Researchers at Breakglass Intelligence discovered an unsecured command-and-control panel in April 2026 that was running stolen credentials against X accounts through automated botnet credential stuffing. In a single 12-minute observation window, the panel tested 722,763 username-password pairs and confirmed 18 new compromises.

Over its full lifetime, the botnet had run more than 4.8 million X accounts through its checker. Two-factor authentication blocked 85.6% of those attempts, underlining just how much that single setting matters — but it also means a meaningful slice got through. By the time researchers took the control panel offline, it had confirmed 138 account compromises out of the 4.8 million attempts, a small percentage that still adds up given industry estimates of roughly 26 billion credential-stuffing attempts hitting login pages worldwide every month.

Running in parallel, a separate scheme has nothing to do with either leaked dataset. Since July 2026, scammers have been sending emails that closely mimic X’s genuine “new device login” alerts — matching logo, colors, and grammar — asking recipients to click a link to “secure” their account, The Guardian reported. Those links lead to fake pages designed to steal passwords or authorize a malicious app. This phishing on X accounts doesn’t require any breach at all; it works purely by tricking people into handing over credentials themselves.

Why does this matter beyond X? It’s a reminder that account-security scares increasingly stem from a mix of old, recycled data and low-effort automated attacks rather than a single dramatic hack — which makes them harder to pin down and easier to underestimate.

Proton’s own outage adds confusion for some users

Adding a wrinkle to an already messy situation, Proton’s email service is independently experiencing a service disruption tied to a hardware failure. Proton Support acknowledged the issue on September 1, 2026, writing that the team was “aware some users are having trouble connecting to Proton services” and was investigating.

Proton’s status page attributed the disruption to residual hardware failures stemming from an overheating incident the week before, along with reduced capacity while engineers bring additional infrastructure online. For X users who rely on a Proton address as their recovery email, that outage could delay a reset message from actually reaching their inbox.

Neither Proton nor independent security researchers have confirmed any direct link between the Proton outage and the X account incidents. The two problems are running on separate tracks, but for anyone whose X account is tied to a Proton inbox, the timing is worth knowing about regardless.

What X users should do right now

X’s own help documentation confirms the platform proactively resets passwords for accounts it flags as compromised or targeted by phishing, sending an email with instructions to the registered address. If a reset lands unprompted, it likely means someone has already tried the account’s credentials, or the account was targeted by one of the phishing emails circulating since July.

X recommends switching two-factor authentication to an authenticator app rather than SMS, using a password unique to X rather than one reused elsewhere, and reviewing active sessions and connected third-party apps for anything unrecognized. The company also urges users to check the sender address before clicking anything — legitimate X emails come only from @x.com or @e.x.com and never ask for a password by email.

One extra safeguard worth activating is the “password reset protect” option, found under the security and account access settings. Turning it on requires verification of the associated email address before any reset request goes out, adding a meaningful barrier against repeated unwanted requests. X also warns users not to respond to unsolicited offers of help around this issue, since scammers are known to exploit exactly this kind of security confusion to steal credentials themselves.

FAQ

Are the unsolicited password reset emails on X a sign of a new data breach?

X has not confirmed a new breach and says its investigation is ongoing. The current wave of emails appears linked to older data leaks and active credential-stuffing attacks rather than a fresh compromise of X’s systems.

What should X users do if they receive unrequested password reset emails?

Users should enable two-factor authentication through an authenticator app, use a password unique to X, review active sessions and connected apps, turn on password reset protect, and avoid clicking links in suspicious messages.

Is there a connection between Proton email service issues and the X password reset problems?

No direct link has been confirmed. Proton’s outage stems from a hardware failure unrelated to the X activity, though it could delay reset emails reaching users who rely on a Proton inbox.

How effective is two-factor authentication against these attacks?

It blocked roughly 85.6% of the credential-stuffing attempts made by the botnet targeting X accounts, making it one of the most effective single defenses users currently have.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Francesco Antonio Russo
Web 3.0 entrepreneur for over 4 years, expert in Cryptocurrencies and Artificial Intelligence. He uses his cross-functional skills for functional and trend-following Social Media Management.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST