Today, X (Twitter) users found their inboxes slammed with legit password reset emails—even though they never asked for them. Here’s the play: attackers are mass-submitting emails, phone numbers, or usernames into X’s password recovery form, triggering a flood of password reset emails from the platform.

What’s Going On

Alongside the password reset spam, some users are also seeing login attempts from other countries and even temporary account locks. This all points to bots using known account identifiers to try and brute-force their way into accounts.

X’s Response

X says there’s no sign of a fresh data leak. The attackers seem to be using old user databases to shotgun reset attempts across tons of accounts. At the same time, phishing emails disguised as official X notifications are making the rounds, upping the odds that someone clicks a malicious link.

Why Crypto Is in the Crosshairs

Crypto folks and projects are already popping up among the targets. Expect to hear about individual account hacks and scammers pushing fake tokens, trying to cash in on the trust built up in compromised profiles.