---
title: "X Users Hit by Barrage of Unsolicited Password Reset Emails"
date: 2026-09-01
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/x-password-reset-attack-crypto-accounts.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# X Users Hit by Barrage of Unsolicited Password Reset Emails

Thousands of X users, including prominent crypto accounts, reported unsolicited password reset emails on Tuesday, September 1. X’s reset flow lets anyone trigger those emails using a public username alone, unless the account holder has switched on Password Reset Protect.

## Key Takeaways

- X users across the crypto industry reported as many as 10 unsolicited reset emails within a few hours.
- X’s reset system accepts a request from any stranger who knows a public username, so the emails prove no leak.
- Password Reset Protect adds a step that makes the requester confirm the account’s email address or phone number.
- Breakglass Intelligence watched a botnet aimed at X accounts test 722,763 logins in 12 minutes in April 2026.

## What We Know?

Crypto investor Nic Carter said many people were receiving unsolicited reset attempts and urged users to switch on Password Reset Protect. Another user, cap.eth, said someone had been “**aggressively**” attempting to reset his password despite two-factor authentication.

At least four CoinDesk staffers reported the same emails, including two whose X email addresses were not widely used. X sends these messages itself. Its [account security page](https://help.x.com/en/safety-and-security/account-security-tips) says the protection prompts a requester “to enter either your email address or phone number” before a reset link goes out.

> A lot of people getting unsolicited X password reset attempts in their email inbox. Do the following:   
>   
> go to X settings -&gt; security and account access -&gt; security -&gt; check "password reset protect" <https://t.co/mOCZCYL7uj>
> 
> — nic carter (@nic\_carter) [September 1, 2026](https://x.com/nic_carter/status/2094781323357327806?ref_src=twsrc%5Etfw)

 ## What We Don’t Know?

[X](https://sqmagazine.co.uk/twitter-users-statistics/) has not commented on the wave or confirmed any security incident. The emails show that reset requests were submitted. They do not show that anyone holds the matching email addresses or passwords.

Four questions stay open: how many accounts were hit, whether one automated source sent the requests, whether a fresh dataset of X addresses is circulating, and whether a flaw allowed the volume.

## The Credential Stuffing Backdrop

Breakglass Intelligence analysts found an exposed command panel in April 2026 run by a botnet built to hijack X accounts. In one 12-minute window it tested **722,763** credentials for 18 new compromises, against **4.8 million** accounts over its lifetime. The analysts logged two-factor authentication on 85.6% of the accounts it touched, and those attempts failed, a result that tracks wider [credential theft](https://sqmagazine.co.uk/password-statistics/) and passkey data.

Older exposure sits underneath. A dataset of more than **200 million** X records including email addresses reached a hacker forum in April 2025, traced to a bug patched in 2022. [Instagram](https://sqmagazine.co.uk/meta-fixes-instagram-ai-flaw-account-takeovers/) saw a near-identical wave in January 2026 and blamed an issue that let outsiders request reset emails.

## SQ Magazine’s Takeaway

The wave points to reconnaissance or harassment aimed at a directory of public usernames. Nothing in it establishes that X’s systems were breached. Crypto handles draw the attention because a hijacked account converts straight into a phishing payload, as [BNB Chain’s followers](https://sqmagazine.co.uk/bnb-chain-x-account-hack-phishing-warning/) learned.

What happens next sits with X, which runs no public security channel and rarely answers individual cases. Users who got one of these emails can review active sessions, move two-factor authentication from SMS to an authenticator app, switch on **Password Reset Protect**, and replace any reused password. None of that prevents a takeover, though the Breakglass sample suggests it helps reduce the risk.