Musk’s X hit by wave of unsolicited password reset emails
Multiple crypto industry figures and Decryptnews staff received unexpected password reset emails on Tuesday, though there is no evidence yet that X itself has been breached.
— Thousands of X users, including prominent cryptocurrency accounts and Decryptnews staff members, reported receiving unsolicited password-reset emails on Tuesday.
— The emails do not necessarily indicate that attackers obtained users’ addresses because X allows anyone to initiate a reset request with a public username.
— Users can enable Password Reset Protect to require confirmation of an account’s email address or phone number, though there is no confirmed evidence of a breach or widespread account takeovers.
A lot of people getting unsolicited X password reset attempts in their email inbox. Do the following: go to X settings -> security and account access -> security -> check «password reset protect» https://t.co/mOCZCYL7uj
— nic carter (@nic_carter) September 1, 2026
Thousands of X users are reporting a wave of unsolicited password reset emails, including several prominent crypto accounts, raising concerns about an attempted account-takeover campaign or possible leak. Individual users received as many as 10 emails within a few hours.
X has an outsized role in the crypto industry, as traders, projects and executives use it as a primary channel for announcements, market commentary, niche trading ideas and breaking news.
Crypto investor Nic Carter said Tuesday that «a lot of people» were receiving unsolicited reset attempts and urged users to switch on X’s Password Reset Protect feature. Another crypto user, cap.eth, said someone had been «aggressively» attempting to reset his password despite having two-factor authentication enabled.
A lot of people getting unsolicited X password reset attempts in their email inbox. Do the following:
go to X settings -> security and account access -> security -> check «password reset protect» https://t.co/mOCZCYL7uj
At least four Decryptnews staffers separately said they received similar emails Tuesday, including two whose email addresses associated with X were not widely used.
That does not necessarily mean attackers have obtained users’ email addresses.
X’s Security terms allow a password reset request to be initiated using a public username, after which X itself sends the reset message to the email address attached to the account. Its Password Reset Protect setting adds another step by requiring the person requesting a reset to confirm the account’s email address or phone number.



There is so far no confirmed evidence of a breach of X’s systems or widespread account takeovers. The company has not publicly commented on the reset attempts, nor has identified any coordinated campaign or security incident.
X has dealt with large-scale account data exposure before. In 2021, attackers exploited an API flaw that linked users’ email addresses and phone numbers to their Twitter accounts. Data tied to more than 200 million accounts later circulated online on darkweb forums in 2023. There is no evidence yet that Tuesday’s password-reset wave is connected to that older breach.
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
Why it matters:
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.


