CoinDesk•
Musk’s X hit by wave of unsolicited password reset emails

A wave of unsolicited password reset requests hit dozens of high-profile cryptocurrency executives, developers, and media personnel on Tuesday, raising immediate alarms across the digital asset sector. Affected individuals, including several journalists at CoinDesk, reported receiving legitimate automated emails from X prompting them to reset their credentials. While initial panic pointed to a potential systemic breach of the social media platform, ongoing analysis suggests the incident is likely an orchestrated harassment campaign or an automated reconnaissance effort rather than an internal system compromise.
From a technical standpoint, triggering X’s password reset endpoint requires only a user’s public handle, email address, or phone number. Bad actors frequently deploy script-driven botnets to flood these publicly accessible recovery portals. This mechanism can serve multiple malicious purposes: probing for valid account-linked identifiers, exhausting rate limits to lock users out during critical trading hours, or setting the stage for sophisticated social engineering attacks. By inundating targets with genuine platform notifications, attackers attempt to create fatigue, hoping the victim will inadvertently approve a fraudulent request or fall prey to a follow-up phishing attempt via SMS or email.
The security implications for the crypto ecosystem are severe, given the industry's heavy reliance on X for real-time market news, project updates, and liquidity deployment. Account Takeover attacks against prominent Web3 figures frequently yield catastrophic financial losses. Once seized, compromised accounts are typically weaponized to distribute malicious smart contract drainers, post fake token launch announcements, or execute market-manipulation schemes. The crypto market remains hyper-sensitive to social media manipulation; earlier this year, a compromised X account belonging to the U.S. Securities and Exchange Commission triggered tens of millions of dollars in liquidations after publishing a fake approval notice for spot Bitcoin ETFs.
Market sentiment following Tuesday's event reflects a growing erosion of trust in the security infrastructure of mainstream social platforms housing critical Web3 communication channels. Security researchers are urging high-value targets to audit their operational security immediately, migrating from SMS-based two-factor authentication to hardware security keys and disconnecting legacy phone numbers from their profiles. As X continues to navigate infrastructure changes under Elon Musk's ownership, the persistent vulnerability of its front-end endpoints to mass automation remains a primary point of friction for institutional market participants who view the platform as both an essential communications hub and an unpredictable single point of failure.
