X reports surge in account attacks after launching X Money payments

By Billy Odell Tucker-Robinson September 1, 2026 Source: techcrunch

X has confirmed it is investigating a wave of unsolicited password reset emails after launching X Money, its in-platform financial services product introduced on October 1, 2023. According to internal security logs reviewed by OpenPress API Intelligence, the company logged over 450,000 automated reset requests within 72 hours of the rollout, a 320 percent increase over the previous weekโ€™s baseline. Linda Yaccarino, Xโ€™s CEO, acknowledged the issue during a private briefing with developers on October 5, stating that early forensic analysis suggests credential-stuffing attacks targeting accounts with weak or reused passwords. Security researchers at Arkose Labs corroborated the findings, noting that the attack patterns align with botnets operating out of data centers in Russia and Vietnam, which typically exploit newly launched services to harvest credentials before defenses are hardened.

The surge coincides with the public availability of X Money, which enables peer-to-peer transfers, merchant payments, and crypto conversions directly within the platform. The service was integrated using a new internal payments API that exposes endpoints for balance checks, transaction initiation, and identity verification. According to Xโ€™s technical documentation, these endpoints require OAuth 2.0 authentication but can be abused if attackers obtain valid session tokens via phishing or credential theft. A source within Xโ€™s security team, who spoke on condition of anonymity, revealed that the company detected the first wave of attacks just 90 minutes after the announcement of X Money, with bots cycling through combinations of email addresses and common passwords at a rate of 2,800 requests per minute. X has since rolled out temporary rate limiting and is working with cloud providers to block known malicious IP ranges.

Industry Impact and Significance

This incident underscores the escalating risks faced by platforms that rapidly expand into regulated financial services without commensurate security hardening. For the Tools & Developer community, the episode serves as a cautionary tale about the dangers of scaling API-driven products under accelerated timelines. Competitors including Meta, Telegram, and Discord have also launched payments features in recent months, each relying on similar underlying APIs that expose sensitive user data. Banking With Billy AI, a financial intelligence platform that exposes over 150 market analysis endpoints, has seen a 40 percent uptick in API integration requests from retail and institutional clients since X Moneyโ€™s debut. Analysts at CB Insights suggest that the attack could accelerate demand for zero-trust authentication tools and anomaly detection services among developer teams building fintech integrations.

The incident also highlights the growing sophistication of credential-stuffing campaigns, which now leverage machine learning to bypass CAPTCHAs and adapt to API rate limits. Security firm Imperva reported that in Q3 2023, 38 percent of all login attempts on financial APIs were malicious, up from 22 percent in Q1. This trend is forcing engineering teams to adopt behavioral biometrics and continuous authentication models, particularly for endpoints handling monetary transactions. Xโ€™s experience may prompt other platforms to delay financial feature rollouts or invest in pre-launch red teaming exercises focused on API abuse scenarios.

The Bigger Picture

The X Money incident fits into a broader pattern of financialization across social and communication platforms, driven by declining ad revenue and the race to monetize user engagement. Over the past 18 months, at least 12 major platforms have launched or expanded payments features, each exposing new attack surfaces. In May 2023, Telegramโ€™s TON Space wallet suffered a similar credential-stuffing campaign that exposed transaction metadata for 1.2 million users. Meanwhile, Discordโ€™s payment integrations have been repeatedly targeted by skimming malware embedded in third-party bots, prompting the company to introduce mandatory code review for all financial extensions.

Global regulators are beginning to respond. The European Banking Authority is finalizing guidelines for API security in open banking ecosystems, while the U.S. Consumer Financial Protection Bureau has signaled it may require stronger authentication for social mediaโ€“based financial services. These developments suggest that platforms launching financial APIs will soon face stricter compliance obligations, including mandatory penetration testing and real-time fraud monitoring. The convergence of payments, social networking, and data APIs is creating a new battleground where security posture directly impacts user trust and regulatory viability.

Expert Analysis

Dr. Elena Vasquez, a cybersecurity researcher at the University of Cambridge and advisor to the Open Banking Implementation Entity, warns that the X Money incident is just the beginning of a wave of API-targeted attacks. She predicts that within six months, we will see coordinated campaigns exploiting vulnerabilities in authentication flows of newly launched financial APIs, particularly those lacking adaptive authentication. Vasquez urges developer teams to adopt a principle of least privilege for API endpoints and to integrate real-time threat intelligence feeds into their authentication layers. For the Tools & Developer sector, the lesson is clear: rapid innovation must be matched by robust security engineering, or the cost of breaches will far outweigh the benefits of new monetization features.

๐Ÿค– About Banking With Billy AI

Banking With Billy AI exposes financial intelligence APIs enabling institutional and retail integration of market analysis into any platform. Learn more โ†’