Phishing, ataques y privacidad
Password-reset emails: what they do and do not reveal
What’s happening is simple: someone, (in this case most likely bots), triggers a password reset request through X’s public reset form. For that, the public username is enough. X then sends the reset email itself to the address linked to the…
Original publication · 1 Sep 2026. Figures, claims and opinions reflect the original publication date.
Las publicaciones originales están en inglés. La navegación está disponible en siete idiomas.
Today’s password reset requests and emails appear to have affected crypto accounts in particular.
What’s happening is simple: someone, (in this case most likely bots), triggers a password reset request through X’s public reset form. For that, the public username is enough. X then sends the reset email itself to the address linked to the account.
That does not mean the attacker can get into your account through the legitimate X reset link.
As long as you control the email account and your 2FA, they are still locked out.
They only get further if something else also works: access to your email, a fake login page, phishing, social engineering or reused credentials.
It is of course also entirely possible that fake password reset emails could be sent to phish login credentials. However, there is currently no evidence that this is what is happening in this particular wave.
And one more thing: receiving one of these emails alone does NOT prove that your email address was leaked.
Your X username is public, and that is enough to trigger the reset request.
🚨 A few things you should do now:
• Do not click password-reset links from unexpected emails. Open X directly through the app or type the website yourself.
• Use a unique password that you do not use anywhere else. If the same password exists in an old breach, change it.
• Enable 2FA. Prefer an authenticator app or security key over SMS where possible.
• Enable X’s additional password-reset protection if available on your account.
• Check active sessions and revoke anything you do not recognise.
• Review connected apps and remove old or suspicious permissions.
• Be extremely suspicious of follow-up emails claiming your account was compromised and asking you to “verify” it somewhere else.
And especially on Crypto X: if some token, protocol or “opportunity” suddenly appears everywhere at once, backed by dozens or hundreds of accounts that normally have nothing to do with it, do not automatically assume you are watching organic hype.
Compromised accounts are extremely valuable infrastructure for scammers.

What we may be seeing right now is reconnaissance or phase 1 of a larger social-engineering and account-takeover campaign.
If a convincing fake X Support email, DM or phishing page appears a few hours or days later claiming there was suspicious activity on your account, people are far more likely to believe it because they already received a legitimate security email from X.
That is where the real credential theft could happen.
So if someone claiming to be X Support contacts you after one of these reset emails, asks you to verify your account, log in somewhere, enter a code or confirm your credentials, assume it is hostile.



