Dailycoin iconDailycoinSep 3, 2026 ~4 min source read

Mass password-recovery attack on X targeted hundreds of thousands; disrupted before takeovers

U.S. Justice Department and X are investigating a large-scale attempt to hijack accounts by abusing password-recovery flows. X says no accounts were captured, but the incident highlights risks for crypto-linked accounts used to spread fake airdrops and scams.

X Password-Recovery Attack Targeted Hundreds of Thousands of Users

Share this story

Send the public story page.

Useful takeaways from this story.

Password-recovery attacks exploit 'forgot password' verification steps (email or SMS) and can scale to many accounts with automation.

Crypto users should treat X accounts as high-value channels and use non-SMS two-factor authentication and X’s Password Reset Protect setting.

# What happened Attorney General Todd Blanche said this week that sophisticated cybercriminals attempted a mass password-recovery attack against hundreds of thousands of X users. X disrupted the campaign before any accounts were captured, and the U.S. Justice Department is collaborating with the company to identify those behind the effort.

# Why this matters for crypto users

# How password-recovery attacks work A password-recovery attack targets the account-reset process instead of trying to guess existing passwords. Common elements include:

  • Triggering "forgot password" flows en masse for many accounts.
  • Exploiting the email or SMS verification step to claim control.
  • Using automation to scale attempts across large lists of usernames or contact points.

Authorities and X have not disclosed which exact technique was used in this incident, whether specific user groups were targeted, or the precise number of accounts hit.

# What X and authorities have said Attorney General Todd Blanche described the perpetrators as "sophisticated cybercriminals" and confirmed X blocked the attempt before accounts were compromised. No additional evidence about methods, identified suspects, or targeted cohorts has been publicly released.

# Practical steps to protect your X account The story lists concrete defensive actions users can take:

  • Turn on Password Reset Protect in X via Settings > Security and account access > Security.
  • Use two-factor authentication with an authenticator app or a hardware security key instead of SMS-based 2FA to reduce exposure to account-recovery attacks via SMS interception or SIM-swapping.

# What remains unclear Key details are still unknown: the specific technical method used, the exact count of accounts targeted, and whether attackers focused on crypto-related or other high-value accounts. The Justice Department and X continue their investigation.

# Bottom line The campaign was stopped before account takeovers occurred, but the event highlights how the account-recovery process can be abused at scale. For users involved in crypto or with sizable followings, securing account-recovery channels and using non-SMS two-factor methods reduces the risk that a hijacked account will be used to spread scams or malicious links.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app