Yesterday afternoon, I—and apparently many others—received a strange email: "Your password on X has been reset. If this wasn't you, please change it immediately." At first glance, it looked like a standard security notice, but here’s the catch: I hadn’t requested a password reset. Even stranger, this wasn’t just happening to me—high-profile figures in the crypto space, including investor Ryan Selkis and even employees of CoinDesk, also received the message.
A mass email blitz, with no one asking for it
Suddenly, hundreds of users were left wondering: "Am I about to get hacked, or is something wrong with X?" The emails looked official—featuring X’s blue logo, a security alert, and a prompt to change passwords. But why did crypto experts and journalists receive these emails? And most importantly, why with no clear reason?
I did some digging and found that I wasn’t the only one affected. Multiple sources reported similar incidents. Some suspected a targeted attack, others a technical glitch. But what was really going on?
No hack—but then what?
X has remained silent so far. No official statement, no technical details. But experts have a few theories:
1. An automated system error? Perhaps X experienced an internal issue that triggered mass password resets. Something similar happened in 2018 when Twitter accidentally sent users into a forced password rotation. This time, however, the emails specifically targeted accounts in the crypto industry.
2. A targeted attack? If attackers had already gained access to user data, they might h
ave tried to take control of accounts by resetting passwords. But so far, there’s no evidence to support this.
3. A clever trick to spread panic? Some users speculate that someone deliberately wanted to create uncertainty—perhaps to distract from real security vulnerabilities later on.
The crypto community is particularly sensitive when it comes to security. After all, millions—or even billions—are at stake. Ryan Selkis commented dryly: "Either this is a massive hack, or someone is trying to make us nervous. Neither is ideal."
What can users do now?
Even though X hasn’t provided any answers, there are steps we can take to stay safe:
- Don’t click the link in the email! Even if the message looks official, it’s safer to go directly to x.com and check for password changes there.
- Enable two-factor authentication (2FA) — if you haven’t already. An extra layer of security is never a bad idea.
- Review accounts — check login history and connected devices to ensure no unauthorized access has occurred.
A mystery without a solution—for now
Whether it was a technical error, a targeted attack, or something else entirely, the cause remains unclear. But one thing is certain: incidents like this erode trust in X, especially in an industry where security is everything.
If it turns out to be a deliberate attack, the consequences could be serious. If it was a bug, it once again shows that even the biggest tech platforms aren’t immune to mistakes.
Until X officially responds, all we can do is stay vigilant—and maybe click a little less on suspicious emails.
📰 Read more
→ OpenAI Ramps Up AI Safety: 700 Malicious Agents Shut Down Faster→ Major Banks Launch Joint Crypto Offensive: Stablecoin for Payment Transactions→ Robinhood’s Crypto Network Generates Millions – Arbitrum Benefits Strongly